8-5
Catalyst 2950 Desktop Switch Software Configuration Guide
78-14982-01
Chapter 8 Configuri ng 802.1X Port-Bas ed Authenticat ion Configuring 802.1X Authentication

Support ed Topo lo gies

The 802 .1X port-ba sed au thentic ation is supp orted in two topologie s:
Point-to-point
Wireless LAN
In a po in t-to- point configur ati on (se e Figu re 8-1 on page 8 -2), only one cl ient can be conne cted to th e
802.1X-enabled switch port. The switch detects the client when the port li nk state changes to the up state.
If a client leaves or is replaced with another client, the switch changes the port link state to down, and
the po rt r etu rns to th e unaut ho riz ed st ate.
Figure 8-3 sh ows 802. 1X p ort- bas ed a uthe ntica tion i n a w ire le ss LA N. T he 8 02. 1X p ort i s configu red
as a multiple-host port that becomes authorized as soon as one client is authenticated. When the port is
authorized, all other hosts indirectly attached to the port are granted access to the network. If the port
becomes unauthorized (re-authentication fails or an EAPOL-logoff message is received), the switch
denies access to the network to all of the attached clients. In this topology, the wireless access point is
responsible for authenticating the clients attached to it, and the wireless access point acts as a client to
the switch.
Figure 8-3 Wireless LAN Example

Configuring 802.1X Authent ication

These sec tions de scri be how t o con figure 8 02. 1X p or t-ba sed a uthe ntic ati on on yo ur sw itch:
Default 80 2.1X Configura tion, pag e 8-6
802.1X Con figuration Gui delines, page 8-7
Enab lin g 8 02.1X A uth en tic ation , pa ge 8 -8 (requ ired)
Configuring the Switch-to-RADIUS-Server Communication, page 8-9 (require d)
Enab ling Pe rio di c Re -Aut hent icat ion, p age 8- 10 (o pt ion al)
Manually Re-Authenticating a Client Connected to a Port, page 8-11 (optional)
Changin g the Quiet Per iod, page 8-11 (optional)
Changing the Switch-to-Client Retransmission Time, page 8-12 (optional)
Setting the Switch-to-Client Frame-Retransmission Number, page 8-13 (optional)
Enabling Multiple Hosts, page 8-13 (optional)
Resetting the 802.1X Configuration to the Default Values, page 8-14 (optional)
Wireless clients
Access point Catalyst 2950 or
3550 switch
Authentication
server
(RADIUS)
74617