show dot1x mac-session

Displays information about the dot1x-MAC-session on each port on the device.
Syntax
show dot1x mac-sessions [ brief | ip-addr ]
Parameters
brief
Displays information about the dot1x-MAC-sessions in brief.
ip-addr
Displays dot1x-mac-session information with an IP address instead of a MAC address.
Modes

User EXEC mode

Privileged EXEC mode

Global configuration mode

Interface configuration mode

dot1x configuration mode

The show dot1x mac-sessions command displays the following information:

Output field Description
Port The port on which the dot1x-MAC-session exists.
MAC/IP (username) The MAC address of the client and the username used for RADIUS authentication.
Vlan The VLAN to which the port is currently assigned.
Auth-State The authentication state of the dot1x-MAC-session. This can be one of the following states:
  • permit - The client has been successfully authenticated, and traffic from the client is being forwarded normally.
  • blocked - Authentication failed for the client, and traffic from the client is being dropped in hardware.
  • restricted - Authentication failed for the client, but traffic from the client is allowed in the restricted VLAN only.
  • init - The client is in is in the process of 802.1X authentication, or has not started the authentication process.
Age The software age of the dot1x-MAC-session.
PAE State The current status of the Authenticator PAE state machine. This state can be INITIALIZE, DISCONNECTED, CONNECTING, AUTHENTICATING, AUTHENTICATED, ABORTING, HELD,FORCE_AUTH, or FORCE_UNAUTH.
Note: When the Authenticator PAE state machine is in the AUTHENTICATING state, if the reAuthenticate, eapStart, eapLogoff, or authTimeout parameters are set to TRUE, it may place the Authenticator PAE state machine indefinitely in the ABORTING state. If this should happen, use the dot1x initialize command to initialize 802.1X authentication on the port, or unplug the client or hub connected to the port, then reconnect it.

The show dot1x mac-session brief command displays the following information:

Output field Description
Port Information about the users connected to each port.
Number of users The number of users connected to the port.
Number of Authorized users The number of users connected to the port that have been successfully authenticated.
Dynamic VLAN Whether the port is a member of a RADIUS-specified VLAN.
Dynamic ACL Whether RADIUS-specified IP ACLs are applied to the port.
Dynamic MAC-Filter Whether RADIUS-specified MAC address filters are applied to the port.
Examples

The following example displays information about the dot1x-MAC-session on each port on the device.

device# show dot1x mac-session
Port MAC/IP(username)           Vlan       Auth      ACL      Age    PAE
State State
-----------------------------------------------------------------------------
4/1/12 0044.0002.0002 :user1    10         permit    none     Ena    AUTHENTICATED
4/1/12 0044.0002.0003 :user2    10         permit    none     Ena    AUTHENTICATED

The following example displays information about the dot1x-MAC-session in brief.

device# show dot1x mac-session brief
Port           Number of    Number of           Dynamic     Dynamic   Dynamic
               users        Authorized users    VLAN        ACL       MAC-Filt
--------------------------------------------------------------------
4/1/12         2            2                    no          no        no