authentication auth-order
authentication
auth-order { dot1x mac-auth |
mac-auth dot1x }no authentication
auth-order { dot1x
mac-auth | mac-auth dot1x
}The authentication sequence is set to perform 802.1X authentication method followed by MAC authentication.
Interface configuration mode
If 802.1X authentication and MAC authentication methods are enabled on the same port, by default the authentication sequence is set to perform 802.1X authentication followed by MAC authentication.
Configuring the authentication order at the interface level overrides the configuration at the global level for that particular interface. The configured global authentication order will still be applicable to other ports that don't have a per port authentication order configured.
For authentication order 802.1X authentication followed by MAC authentication: When 802.1X authentication succeeds, the client is authenticated and the policies returned by the RADIUS server are applied. MAC authentication is not performed in this case. If 802.1X authentication fails, the failure action is carried out and MAC authentication is not attempted. On the other hand, if the client does not respond to dot1x messages, then MAC authentication is attempted. Upon successful MAC authentication, the client is authenticated and the policies returned by the RADIUS server are applied and on authentication failure, the configured failure action is applied.
For authentication order MAC authentication followed by 802.1X authentication: By
default, 802.1X authentication is performed even if MAC authentication is successful.
Upon successful 802.1X authentication, the client is authenticated and the policies
returned by the RADIUS server are applied and on authentication failure, the configured
failure action is applied. The default behavior can be changed by specifying the RADIUS
attribute, to prevent the 802.1X authentication from being performed after successful
MAC authentication. In this case, the client is authenticated and the policies returned
by the RADIUS server are applied after successful MAC authentication. If MAC authentication
method fails, 802.1X port security authentication is not attempted and the configured
failure action is applied. However, if the
mac-authentication dot1x-override command is configured, the clients that failed MAC authentication undergoes 802.1X
authentication if the failure action is configured as restricted VLAN. If 802.1X authentication
is successful, the policies returned by the RADIUS server are applied to the port.
The
no form of the command disables the authentication order functionality.
The following example specifies 802.1X authentication followed by MAC authentication as the order of authentication methods on Ethernet interface 1/1/3.
device(config)# authentication device(config-authen)# interface ethernet 1/1/3 device(config-if-e1/1/3)# authentication auth-order dot1x mac-auth
| Release version | Command history |
|---|---|
| 08.0.20 | This command was introduced. |