authentication filter

Applies an 802.1X authentication override filter to permit or deny traffic from a specified MAC address or set of MAC addresses.
Syntax
authentication filter { permit | deny } { MAC_address address_mask vlan_id }
no authentication filter { permit | deny } { MAC_address address_mask vlan_id }
Command Default

By default, on an interface with Flexible authentication configured, 802.1x authentication is applied.

Parameters
{ permit | deny }
Determines whether the MAC address provided in the filter statement is allowed or dropped.
MAC_address address_mask
Specifies the MAC address (in the form HHHH.HHHH.HHHH) followed by a mask (in the form xxxx.xxxx.xxxx, where x is "0" or "f") to be matched in the filter statement.
vlan_id
Specifies the VLAN number in which the 802.1X authentication override is allowed.
Modes

Interface configuration sub-mode

Usage Guidelines

The no form of the command removes the 802.1X authentication override filter.

Examples

The following example configures 802.1X authentication override on port 1/1/3 for all traffic from MAC source address 001.1234.1234 in VLAN 10.

device# configure terminal
device(config)# interface ethernet 1/1/3
device(config-if-e1000-1/1/3)# authentication filter permit 0001.1234.1234 ffff.ffff.ffff 10
device(config-if-e1000-1/1/3)# exit
device(config)#
History
Release version Command history
08.0.95 This command was introduced.