7-7
Catalyst 3550 Multilayer Switch Software Configuration Guide
78-11194-03
Chapter7 Configuring 802.1X Port-B as ed Authentication Configuring 802.1X Authentication
802.1X Configuration Guidelines
These are the 802.1X authentication configuration guidelines:
When 802.1X is enabled, ports are authenticated before any other Layer 2 or Layer 3 features are
enabled.
The 802.1X protocol is supported on both Layer 2 static-access ports a nd Layer 3 routed ports, but
it is not supported on these port types:
Trunk port—If you try to enable 802.1X on a trunk port, an error message appears, and 802 .1X
is not enabled. If you try to change the mode of an 802.1X-enabled port to trunk, the port mode
is not changed.
Dynamic ports—A port in dynamic mode can negotiate with its neighbor to become a trunk
port. If you try to enable 802.1X on a dynamic port, an e rror m essage app ea rs, a nd 802. 1X is
not enabled. If you try to change the mode of an 802.1X-enabled port to dynamic, the port mode
is not changed.
Dynamic-access ports—If you try to enable 802.1X on a dynamic-access (VLAN Query
Protocol [VQP]) port, an error message appears, and 802.1X is not enabled. If you try to change
an 802.1X-enabled port to dynamic VLAN assignment, a n error m es sag e ap pe ars, an d th e
VLAN configuration is not changed.
EtherChannel port—Before enabling 802.1X on the port, you must fi rst re move i t f rom t he
EtherChannel. If you try to enable 802.1X on an EtherC hanne l or o n a n acti ve p ort in a n
EtherChannel, an error message appears, and 802.1X is not enabled . If you enable 802.1X on a
not-yet active port of an EtherChannel, the port does not join the EtherChannel.
Secure port—You cannot configure a secure port as an 802.1X port. If you try to enable 802.1X
on a secure port, an error message appears, and 802.1X is not enabled. If you try to change an
802.1X-enabled port to a secure port, an error message appears, and the security settings are not
changed.
Switch Port Analyzer (SPAN) destination port—You can enable 802.1X on a port that is a SPAN
destination port; however, 802.1X is disabled until the port is removed as a SPAN destination.
You can enable 802.1X on a SPAN source port.