Configuring Port-Based and Client-Based Access Control (802.1X)

Configuring Switch Ports as 802.1X Authenticators

3. Configure the 802.1X Authentication Method

This task specifies how the switch will authenticate the credentials provided by a supplicant connected to a switch port configured as an 802.1X authenti- cator.

Syntax: aaa authentication port-access < local eap-radius chap-radius >

Determines the type of RADIUS authentication to use.

local Use the switch’s local username and password for supplicant authentication.

eap-radiusUse EAP-RADIUS authentication. (Refer to the documentation for your RADIUS server.)

chap-radiusUse CHAP-RADIUS (MD-5) authentication. (Refer to the documentation for your RADIUS server appli- cation.)

For example, to enable the switch to perform 802.1X authentication using one or more EAP-capable RADIUS servers:

Configuration command for EAP-RADIUS authentication.

802.1X (Port-Access) configured for EAP- RADIUS authentication.

Figure 8-5. Example of 802.1X (Port-Access) Authentication

8-23