Configuring Port-Based Access Control (802.1x)

Configuring Switch Ports as 802.1x Authenticators

3. Configure the 802.1x Authentication Method

This task specifies how the switch will authenticate the credentials provided by a supplicant connected to a switch port configured as an 802.1x authenti- cator.

Syntax: aaa authentication port-access < local eap-radius chap-radius >

Determines the type of RADIUS authentication to use.

local

Use the switch’s local username and password for sup­ plicant authentication.

eap-radius

Use EAP-RADIUS authentication. (Refer to the docu­ mentation for your RADIUS server.)

chap-radius

Use CHAP-RADIUS (MD-5) authentication. (Refer to the documentation for your RADIUS server applica­ tion.)

For example, to enable the switch to perform 802.1x authentication using one or more EAP-capable RADIUS servers:

Configuration command for EAP-RADIUS authentication.

802.1x (Port-Access) configured for EAP- RADIUS authentication.

Figure 6-3. Example of 802.1x (Port-Access) Authentication

6-18