Chapter 10 Configuring IEEE 802.1x Port-Based Authentication

Configuring IEEE 802.1x Authentication

Command

Step 10 dot1x fallback fallback-profile

Step 11

exit

Step 12

 

show dot1x interface interface-id

Step 13

 

copy running-config startup-config

Purpose

Configure the port to authenticate a client by using web authentication when no IEEE 802.1x supplicant is detected on the port. Any change to the fallback-profile global configuration takes effect the next time IEEE 802.1x fallback is invoked on the interface.

Note Web authorization cannot be used as a fallback method for IEEE 802.1x if the port is configured for multidomain authentication.

Return to privileged EXEC mode.

Verify your configuration.

(Optional) Save your entries in the configuration file.

This example shows how to configure IEEE 802.1x authentication with web authentication as a fallback method.

Switch(config) configure terminal

Switch(config)# ip admission name rule1 proxy http

Switch(config)# fallback profile fallback1

Switch(config-fallback-profile)# ip access-groupdefault-policy in

Switch(config-fallback-profile)# ip admission rule1

Switch(config-fallback-profile)# exit

Switch(config)# interface gigabit1/0/1

Switch(config-if)#switchport mode access

Switch(config-if)#dot1x port-control auto

Switch(config-if)#dot1x fallback fallback1

Switch(config-if)# end

For more information about the ip admission name and dot1x fallback commands, see the command reference for this release.

Disabling IEEE 802.1x Authentication on the Port

You can disable IEEE 802.1x authentication on the port by using the no dot1x pae interface configuration command.

Beginning in privileged EXEC mode, follow these steps to disable IEEE 802.1x authentication on the port. This procedure is optional.

 

Command

Purpose

Step 1

 

 

configure terminal

Enter global configuration mode.

Step 2

 

 

interface interface-id

Specify the port to be configured, and enter interface configuration mode.

Step 3

 

 

no dot1x pae

Disable IEEE 802.1x authentication on the port.

Step 4

 

 

end

Return to privileged EXEC mode.

Step 5

 

 

show dot1x interface interface-id

Verify your entries.

Step 6

 

 

copy running-config startup-config

(Optional) Save your entries in the configuration file.

 

 

 

To configure the port as an IEEE 802.1x port access entity (PAE) authenticator, which enables

IEEE 802.1x on the port but does not allow clients connected to the port to be authorized, use the dot1x pae authenticator interface configuration command.

 

 

Catalyst 3750-E and 3560-E Switch Software Configuration Guide

 

 

 

 

 

 

OL-9775-02

 

 

10-43

 

 

 

 

 

Page 295
Image 295
Cisco Systems 3750E manual Disabling Ieee 802.1x Authentication on the Port, Dot1x fallback fallback-profile, 10-43