9-44
Cisco Catalyst Blade Switch 3130 for Dell Software Configuration Guide
OL-13270-01
Chapter9 Configuring IEEE 802.1x Port-Based Authentication
Configuring IEEE 802.1x Authentication
This example shows how to configure IEEE 802.1x authentication with web authen ticati on as a f allb ack
method.
Switch(config) configure terminal
Switch(config)# ip admission name rule1 proxy http
Switch(config)# fallback profile fallback1
Switch(config-fallback-profile)# ip access-group default-policy in
Switch(config-fallback-profile)# ip admission rule1
Switch(config-fallback-profile)# exit
Switch(config)# interface gigabitethernet1/0/1
Switch(config-if)# switchport mode access
Switch(config-if)# dot1x port-control auto
Switch(config-if)# dot1x fallback fallback1
Switch(config-if)# end
For more information about the ip admission name and dot1x fallback commands, see the command
reference for this release. For more information about the ip admission name and ip a ccess-group
commands, see the Network Admission Control Software Configuration Guide on Cisco.com.
Disabling IEEE 802.1x Authentication on the Port
You can disable IEEE 802.1x authentication on the port by using the no dot1x pae interface
configuration command.
Beginning in privileged EXEC mode, follow these steps to disable IEEE 80 2. 1x auth en tica tio n o n the
port. This procedure is optional.
Step9 dot1x port-control auto Enable IEEE 802.1x authentication on the interface.
Step10 dot1x fallback fallback-profile Configure the port to authenticate a client by using web
authentication when no IEEE 802.1x supplicant is detected on th e
port. Any change to the fallback-profile global configuration takes
effect the next time IEEE 802.1x fallback is invoked on the interface.
Note Web authorization cannot be used as a fallback method for
IEEE 802.1x if the port is configured for multidomain
authentication.
Step11 exit Return to privileged EXEC mode.
Step12 show dot1x interface interface-id Verify your configuration.
Step13 copy running-config startup-config (Optional) Save your entries in the configuration file.
Command Purpose
Command Purpose
Step1 configure terminal Enter global configuration mode.
Step2 interface interface-id Specify the port to be configured, and enter interface configuration mo de.
Step3 no dot1x pae Disable IEEE 802.1x authentication on the port.
Step4 end Return to privileged EXEC mode.
Step5 show dot1x interface interface-id Verify your entries.
Step6 copy running-config startup-config (Optional) Save your entries in the configuration file.