Configuring Port-Based and Client-Based Access Control (802.1X)
Contents
3. Configure the 802.1X Authentication Method . . . . . . . . . . . . . . . . 10-21
4. Enter the RADIUS Host IP Address(es) . . . . . . . . . . . . . . . . . . . . . 10-22
5. Enable 802.1X Authentication on the Switch . . . . . . . . . . . . . . . . 10-23
6. Optionally Resetting Authenticator Operation . . . . . . . . . . . . . . . 10-23
802.1X Open VLAN Mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-24
Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-24
VLAN Membership Priorities . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-25
Use Models for 802.1X Open VLAN Modes . . . . . . . . . . . . . . . . . . . . 10-26
Operating Rules for Authorized-Client and
Unauthorized-Client VLANs
. . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-31
Setting Up and Configuring 802.1X Open VLAN Mode . . . . . . . . . . . 10-35
802.1X Open VLAN Operating Notes . . . . . . . . . . . . . . . . . . . . . . . . . 10-39
Option For Authenticator Ports: Configure Port-Security
To Allow Only 802.1X-Authenticated Devices . . . . . . . . . . . . . . . . . 10-40
Port-Security . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-41
Configuring Switch Ports To Operate As Supplicants for 802.1X
Connections to Other Switches . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-42
Example . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-42
Supplicant Port Configuration . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-44
Displaying 802.1X Configuration, Statistics, and Counters . . . . 10-46
Show Commands for Port-Access Authenticator . . . . . . . . . . . . . . . 10-46
Viewing 802.1X Open VLAN Mode Status . . . . . . . . . . . . . . . . . . . . . 10-48
Show Commands for Port-Access Supplicant . . . . . . . . . . . . . . . . . . 10-52
How RADIUS/802.1X Authentication Affects VLAN Operation . 10-53
Operating Notes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 10-57
Messages Related to 802.1X Operation . . . . . . . . . . . . . . . . . . . . . . . 10-58
10-2