106 Configuring and managing ports and VLANs
NN47250-500 (Version 03.01)
from sending traffic directly to an authenticator’s MAC address until the client is authenticated. Instead of
sending traffic to the authenticator’s MAC address, the client sends packets to the PAE group address. The
802.1X specification prohibits networking devices from forwarding PAE group address packets, because this
would make it possible for multiple authenticators to acquire the same client.
For non-802.1X clients, who use MAC authentication, Web-based AAA, or last-resort authentication, wired
authentication works if the clients are directly attached or indirectly attached.

Clearing a port

To change a port’s type from AP access port or wired authentication port, you must first clear the port, then set
the port type.
Clearing a port removes all the port’s configuration settings and resets the port as a network port.
If the port is an AP access port, clearing the port disables PoE and 802.1X authentication.
If the port is a wired authenticated port, clearing the port disables 802.1X authentication.
If the port is a network port, the port must first be removed from all VLANs, which removes the port from
all spanning trees, load-sharing port groups, and so on.
To clear a port, use the following command:
clear port type port-list
For example, to clear the port-related settings from port 5 and reset the port as a network port, type the
following command:
WSS# clear port type 5
This may disrupt currently authenticated users. Are you sure? (y/n) [n]y
success: change accepted.
Note. If clients are connected to a wired authentication port through a downstream
third-party switch, the WSS attempts to authenticate based on any traffic coming from the
switch, such as Spanning Tree Protocol (STP) BPDUs. In this case, disable repetitive traffic
emissions such as STP BPDUs from downstream switches. If you want to provide a
management path to a downstream switch, use MAC authentication.
Caution! When you clear a port, WSS Software ends user sessions that are using the
port.
Note. A cleared port is not placed in any VLANs, not even the default VLAN (VLAN 1).