2-308
Catalyst 6500 Series Switch Command Reference—Release8.4
OL-6244-01
Chapter2 Catalyst 6500 Series Switch and ROM Monitor Commands
set dot1x
Defaults The default settings are as follows:
system-auth-control is enabled.
quiet-period is 60 seconds.
tx-period is 30 seconds.
re-authperiod is 3600 seconds.
supp-timeout is 30 seconds.
server-timeout is 30 seconds.
max-req count is 2.
shutdown-timeout is 300 seconds.
radius-accounting is disabled.
radius-vlan-assignment is disabled.
radius-keepalive is enabled.
Command Types Switch command.
Command Modes Privileged.
Usage Guidelines When you set the system-auth-control, the following applies:
The enable keyword allows you to control each port’s authorization status per the port-control
parameter set using the set port dot1x command.
The disable keyword allows you to make all ports behave as though the port-control para me ter i s
set to force-authorized.
If you do not enable reauth entication, reauthentication does not automatically occur after authentication has
occurred.
Private VLANs and 802.1X configurations are mutually exclusive of one another.
When the supplicant does not notify the authenticator that it received the EAP-request/identity packet,
the authenticator waits a period of time (set by entering the tx-period seconds parameter), and then
retransmits the packet.
When the supplicant does not notify the backend authenticator that it received the EAP-request packet,
the backend authenticator waits a period of time (set by entering the supp-timeout seconds parameter),
and then retransmits the packet.
When the authentication server does not notify the backend authenticator that it received specific
packets, the backend authenticator waits a period of time (set by entering the server-timeout seconds
parameter), and then retransmits the packets.
When you enter the set dot1x dhcp-relay-agent command, you can enter more than one VLAN.
radius-vlan-assignment Specifies 802.1X RADIUS VLAN assignment.
radius-keepalive Specifies 802.1X RADIUS keepalive state.