Software Configuration Guide—Release 15.0(2)SG
Chapter 40 Configuring 802.1X Port-Based Authentication Configuring 802.1X Port-Based Authentication
This example shows how to enable a regular VLAN 40 on Fast Ethernet 4/3 as a authentication-failed
VLAN on a static access port:
Cisco IOS Release 12.2(50)SG and later
Switch# configure terminal
Switch(config)# interface gigabitEthernet3/1
Switch(config-if)# switchport mode access
Switch(config-if)# dot1x pae authenticator
Switch(config-if)# authentication port-control auto
Switch(config-if)# authentication event fail retry 5 action authorize vlan 40
Switch(config-if)# end
Switch# show dot1x all
Sysauthcontrol Enabled
Dot1x Protocol Version 2
Dot1x Info for GigabitEthernet3/1
PortControl = AUTO
ControlDirection = Both
QuietPeriod = 60
ServerTimeout = 0
SuppTimeout = 30
ReAuthMax = 2
MaxReq = 2
TxPeriod = 30
Step 5 Cisco IOS Release 12.2(50)SG and later
Switch(config-if)# authentication
event fail action authorize vlan
Cisco IOS Release 12.2(46)SG or earlier
Switch(config-if)# dot1x auth-fail
vlan vlan-id
Enables authentication-failed VLAN on a particular interface.
To disable the authentication-failed VLAN feature on a particular port,
use the no authentication event fail action authorize vlan interface
configuration command.
Step 6 Cisco IOS Release 12.2(50)SG and later
Switch(config-if)# authentication
event fail retry max-attempts
action [authorize vlan vlan-id |
Cisco IOS Release 12.2(46)SG or earlier
Switch(config-if)# dot1x auth-fail
max-attempts max-attempts
Configure a maximum number of attempts before the port is moved to
authentication-failed VLAN.
Default is 3 attempts.
Step 7 Switch(config-if)# end Returns to configuration mode.
Step 8 Switch(config)# end Returns to privileged EXEC mode.
Step 9 Switch# show dot1x interface
interface-id details (Optional) Verifies your entries.
Step 10 Switch# copy running-config
startup-config (Optional) Saves your entries in the configuration file.
Command Purpose