Chapter 10 Configuring IEEE 802.1x Port-Based Authentication

Configuring IEEE 802.1x Authentication

Default IEEE 802.1x Authentication Configuration

Table 10-2shows the default IEEE 802.1x authentication configuration.

Table 10-2 Default IEEE 802.1x Authentication Configuration

 

 

 

 

Feature

Default Setting

 

 

 

 

 

 

 

 

 

 

 

 

Switch IEEE 802.1x enable state

Disabled.

 

 

 

 

 

 

 

 

 

 

 

 

Per-port IEEE 802.1x enable state

Disabled (force-authorized).

 

 

 

 

 

 

 

The port sends and receives normal traffic without IEEE

 

 

 

 

 

 

 

802.1x-based authentication of the client.

 

 

 

 

 

 

 

 

 

 

 

 

AAA

Disabled.

 

 

 

 

 

 

 

 

 

 

 

 

 

RADIUS server

 

 

 

 

 

 

 

IP address

None specified.

 

 

 

 

 

UDP authentication port

1812.

 

 

 

 

 

Key

None specified.

 

 

 

 

 

 

 

 

 

 

 

 

Host mode

Single-host mode.

 

 

 

 

 

 

 

 

 

 

 

 

Control direction

Bidirectional control.

 

 

 

 

 

 

 

 

 

 

 

 

Periodic re-authentication

Disabled.

 

 

 

 

 

 

 

 

 

 

 

 

Number of seconds between

3600 seconds.

 

 

 

 

 

re-authentication attempts

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Re-authentication number

2 times (number of times that the switch restarts the

 

 

 

 

 

 

 

authentication process before the port changes to the

 

 

 

 

 

 

 

unauthorized state).

 

 

 

 

 

 

 

 

 

 

 

 

Quiet period

60 seconds (number of seconds that the switch remains in

 

 

 

 

 

 

 

the quiet state following a failed authentication exchange

 

 

 

 

 

 

 

with the client).

 

 

 

 

 

 

 

 

 

 

 

 

Retransmission time

30 seconds (number of seconds that the switch should

 

 

 

 

 

 

 

wait for a response to an EAP request/identity frame

 

 

 

 

 

 

 

from the client before resending the request).

 

 

 

 

 

 

 

 

 

 

 

 

Maximum retransmission number

2 times (number of times that the switch will send an

 

 

 

 

 

 

 

EAP-request/identity frame before restarting the

 

 

 

 

 

 

 

authentication process).

 

 

 

 

 

 

 

 

 

 

 

 

Client timeout period

30 seconds (when relaying a request from the

 

 

 

 

 

 

 

authentication server to the client, the amount of time the

 

 

 

 

 

 

 

switch waits for a response before resending the request

 

 

 

 

 

 

 

to the client.)

 

 

 

 

 

 

 

 

 

 

 

 

Authentication server timeout period

30 seconds (when relaying a response from the client to

 

 

 

 

 

 

 

the authentication server, the amount of time the switch

 

 

 

 

 

 

 

waits for a reply before resending the response to the

 

 

 

 

 

 

 

server. This setting is not configurable.)

 

 

 

 

 

 

 

 

 

 

 

 

Guest VLAN

None specified.

 

 

 

 

 

 

 

 

 

 

 

 

Inaccessible authentication bypass

Disabled.

 

 

 

 

 

 

 

 

 

 

 

 

Restricted VLAN

None specified.

 

 

 

 

 

 

 

 

 

 

 

 

Catalyst 3750-E and 3560-E Switch Software Configuration Guide

 

 

 

 

 

 

 

 

 

 

10-22

 

 

 

 

 

OL-9775-02

 

 

 

 

 

 

 

 

Page 274
Image 274
Cisco Systems 3750E manual Default Ieee 802.1x Authentication Configuration, Aaa, 10-22