6

Configuring Port-Based Access Control (802.1x)

Contents

Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-2

How 802.1x Operates . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-5

Terminology . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-7

General Operating Rules and Notes . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-9

General Setup Procedure for Port-Based Access Control (802.1x)

Do These Steps Before You Configure 802.1x Operation . . . . . . . . . 6-11

Overview: Configuring 802.1x Authentication on the Switch . . . . . . 6-12

Configuring Switch Ports as 802.1x Authenticators . . . . . . . . . . 6-15802.1x Open VLAN Mode

Introduction . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-20

Operating Rules for Authorized-Client and 

Unauthorized-Client VLANs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-24Setting Up and Configuring 802.1x Open VLAN Mode . . . . . . . . . . . . 6-26802.1x Open VLAN Operating Notes . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-30

Option For Authenticator Ports: Configure Port-Security To Allow Only 802.1x Devices . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-31

Configuring Switch Ports To Operate As Supplicants for 802.1x Connections to Other Switches . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-33

Displaying 802.1x Configuration, Statistics, and Counters . . . . . . 6-37Show Commands for Port-Access Authenticator . . . . . . . . . . . . . . . . 6-37Viewing 802.1x Open VLAN Mode Status . . . . . . . . . . . . . . . . . . . . . . . 6-38Show Commands for Port-Access Supplicant . . . . . . . . . . . . . . . . . . . 6-42

How RADIUS/802.1x Authentication Affects VLAN Operation . . 6-43

Messages Related to 802.1x Operation . . . . . . . . . . . . . . . . . . . . . . . . 6-47

6-1