Configuration Commands

Table 102 802.1x Global Configuration commands

Command

Description

 

 

show dot1x

Displays current global 802.1x parameters.

 

Command mode: All

 

 

802.1x Port configuration

The 802.1x port commands allow you to configure parameters that affect the selected port in the switch. These settings override the global 802.1x parameters.

The following table describes the 802.1x Port Configuration commands. Table 103 802.1x Port Configuration commands

Command

Description

 

 

dot1x mode {[force-unauthorized

Sets the type of access control for the port:

autoforce-authorized]}

force-unauth—the port is unauthorized unconditionally.

 

 

auto—the port is unauthorized until it is successfully authorized

 

by the RADIUS server.

 

force-auth—the port is authorized unconditionally, allowing

 

all traffic.

 

The default value is force-auth.

 

Command mode: Interface port

 

 

dot1x quiet-time {<0-65535>}

Sets the time, in seconds, the authenticator waits before transmitting

 

an EAP-Request/Identity frame to the supplicant (client) after an

 

authentication failure in the previous round of authentication. The

 

default value is 60 seconds.

 

Command mode: Interface port

 

 

dot1x transmit-interval

Sets the time, in seconds, the authenticator waits for an EAP-

{<1-65535>}

Response/Identity frame from the supplicant (client) before

 

retransmitting an EAP-Request/Identity frame. The default value is

 

30 seconds.

 

Command mode: Interface port

 

 

dot1x supplicant-timeout

Sets the time, in seconds, the authenticator waits for an EAP-

{<1-65535>}

Response packet from the supplicant (client) before retransmitting

 

the EAP-Request packet from the authentication server. The default

 

value is 30 seconds.

 

Command mode: Interface port

 

 

dot1x server-timeout {<1-65535>}

Sets the time, in seconds, the authenticator waits for a response

 

from the RADIUS server before declaring an authentication timeout.

 

The default value is 30 seconds.

 

Command mode: Interface port

 

 

dot1x max-request {<1-10>}

Sets the maximum number of times the authenticator retransmits an

 

EAP-Request packet to the supplicant (client). The default value is 2.

 

Command mode: Interface port

 

 

128