Security: 802.1X Authentication
802.1X Configuration Through the GUI
Cisco Small Business 200, 300 and 500 Series Managed Switch Administration Guide (Internal Version) 399
19
After an authentication failure, and if guest VLAN is activated globally on
a given port, the guest VLAN is automatically assigned to the
unauthorized ports as an Untagged VLAN.
-Cleared—Disables guest VLAN on the port .
802.1X Based Authentication—802.1X authentication is the only
authentication method performed on the port.
MAC Based Authentication—Port is authenticated based on the supplicant
MAC address. Only 8 MAC-based authentications can be used on the port.
NOTE For MAC authentication to succeed, the RADIUS server supplicant
username and password must be the supplicant MAC address. The MAC
address must be in lower case letters and entered without the . or -
separators; for example: 0020aa00bbcc.
Web Based Authentication—This is only available in Layer 2 switch mode.
Select to enable web-based authentication on the switch.
Periodic Reauthentication—Select to enable port re-authentication
attempts after the specified Reauthentication Period.
Reauthentication Period—Enter the number of seconds after which the
selected port is reauthenticated.
Reauthenticate Now—Select to enable immediate port re-authentication.
Authenticator State—Displays the defined port authorization state. The
options are:
-Initialize—In proces s of coming up.
-Force-Auth orized—Controlled port state is set to Force-Authorized
(forward traffic).
-Force-Unauth orized—Controlled port state is set to Force-Unauthorized
(discard traffic).
NOTE If the port is not in Force-Authorized or Force-Unauthorized, it is in
Auto Mode and the authenticator displays the state of the authentication
in progress. After the port is authenticated, the state is shown as
Authenticated.
Time Range—Enable a limit on the time that the specific port is authorized
for use if 802.1x has been enabled (Port -Based authentication is checked).
Time Range Name—Select the profile that specifies the time range.