29-16
Software Configuration Guide—Release 12.2(25)SG
OL-7659-03
Chapter29 Understanding and Configuring 802.1X Port-Based Authentication
How to Configure 802.1X
Enabling 802.1X Authentication
To enable 802.1X port-based authentication, you first must enable 802.1X globally on your switch, then
enable AAA and specify the authentication method list. A method list describes the sequence and
authentication methods that must be queried to authenticate a user.
The software uses the first method listed in the method list to authenticate use rs; if that method fails to
respond, the software selects the next authentication method in the list. This process continues until there
is successful communication with a listed authentication method or until all defined methods are
exhausted. If authentication fails at any point in this cycle, the authentication process stops, and no other
authentication methods are attempted.
To allow VLAN assignment, you must enable AAA authorization to configure the switch for all
network-related service requests.
To configure 802.1X port-based authentication, perform this task:
Command Purpose
Step1 Switch# configure terminal Enters global configuration mode.
Step2 Switch(config)#
[no] dot1x system-auth-control
Enables the 802.1X feature on your switch.
Step3 Switch(config)# aaa new-model Enables AAA.
Step4 Switch(config)# aaa authentication
dot1x {default}
method1
[
method2
...] Creates an 802.1X authentication method list.
To create a default list that is used when a named list is not specified in
the authentication command, use the default keyword followed by the
methods that are to be used in default situations. The default method list
is automatically applied to all interfaces.
Enter at least one of these keywords:
group radius—Use the list of all RADIUS servers for authentication.
none—Use no authentication. The client is automatically
authenticated by the switch without using the information supplied by
the client.
Step5 Switch(config)# aaa authorization
network {default} group radius
(Optional) Configure the switch for user RADIUS authorization for all
network-related service requests, such as VLAN assignment.
Step6 Switch(config)# interface
interface-id
Enters interface configuration mode and specifies the interface to be
enabled for 802.1X authentication.
Step7 Switch(config-if)# dot1x
port-control auto
Enables 802.1X authentication on the interface.
For feature interaction information with trunk, dynamic, dynamic-access,
EtherChannel, secure, and SPAN ports, see the “802.1X Configuration
Guidelines” section on page29-15.
Step8 Switch(config-if)# end Returns to privileged EXEC mode.
Step9 Switch # show dot1x all Verifies your entries.
Check the Status column in the 802.1X Port Summary section of the
display. An enabled status means that the port-control value is set either
to auto or to force-unauthorized.