9-20
Catalyst 2960 Switch SoftwareConfiguration Guide
78-16881-01
Chapter9 Configuring IEEE 802.1x Port-Based Authentication
Configuring IEEE 802.1x Authentication
Beginning in privileged EXEC mode, follow these steps to enable the optional guest VLAN behavior
and to configure a guest VLAN. This procedure is optional.
To disable the optional guest VLAN behavior, use the no dot1x guest-vlan supplicant global
configuration command. To remove the guest VLAN, use the no dot1x guest-vlan interface
configuration command. If the port is currently authorized in the guest VLAN, the port returns to the
unauthorized state.
This example shows how enable the optional guest VLAN behavior and to specify VLAN 5 as an IEEE
802.1x guest VLAN:
Switch(config)# dot1x guest-vlan supplicant
Switch(config)# interface gigabitethernet0/1
Switch(config-if)# dot1x guest-vlan 5
Resetting the IEEE 802.1x Configuration to the Default Values
Beginning in privileged EXEC mode, follow these steps to reset the IEEE 802.1x configuration to the
default values. This procedure is optional.
Command Purpose
Step1 configure terminal Enter global configuration mode.
Step2 dot1x guest-vlan supplicant Enable the optional guest VLAN behavior globally on the switch.
Step3 interface interface-id Specify the port to be configured, and enter interface configuration mode.
For the supported port types, see the “IEEE 802.1x Configuration
Guidelines” section on page 9-12.
Step4 dot1x guest-vlan vlan-id Specify an active VLAN as an IEEE 802.1x guest VLAN. The range is 1
to 4094.
You can configure any active VLAN except an RSPAN VLAN or a voice
VLAN as an IEEE 802.1x guest VLAN.
Step5 end Return to privileged EXEC mode.
Step6 show dot1x interface interface-id Verify your entries.
Step7 copy running-config startup-config (Optional) Save your entries in the configuration file.
Command Purpose
Step1 configure terminal Enter global configuration mode.
Step2 interface interface-id Enter interface configuration mode, and specify the port to be configured.
Step3 dot1x default Reset the IEEE 802.1x parameters to the default values.
Step4 end Return to privileged EXEC mode.
Step5 show dot1x interface interface-id Verify your entries.
Step6 copy running-config startup-config (Optional) Save your entries in the configuration file.