Configuring
802.1X Open VLAN Mode
■ A client must either have a valid IP address configured before connecting to the switch, or download one through the Unauthorized- Client VLAN from a DHCP server. In the latter case, you will need to provide DHCP services on the
■ Ensure that the switch is connected to a RADIUS server configured
| to support authentication requests from clients using ports config- |
| ured as 802.1X authenticators. (The RADIUS server should not be on |
| the |
| Note that as an alternative, you can configure the switch to use local |
| password authentication instead of RADIUS authentication. However, |
| this is less desirable because it means that all clients use the same |
| passwords and have the same access privileges. Also, you must use 802.1X |
| supplicant software that supports the use of local switch passwords. |
|
|
Caution | Ensure that you do not introduce a security risk by allowing Unauthorized- |
| Client VLAN access to network services or resources that could be compro- |
| mised by an unauthorized client. |
|
|
Configuring General 802.1X Operation: These steps enable 802.1X authentication, and must be done before configuring 802.1X VLAN operation.
1.Enable 802.1X authentication on the individual ports you want to serve as authenticators. (The switch automatically disables LACP on the ports on which you enable 802.1X.) On the ports you will use as authenticators with VLAN operation, ensure that the (default)
Syntax: aaa
Activates 802.1X