show mac-authentication configuration

Displays the global or interface level MAC authentication configuration.
Syntax
show mac-authentication configuration [ all | stack-unit id | ethernet unit/slot/port ]
Parameters
all
Displays the MAC authentication configuration on all interfaces.
ethernet unit/slot/port
Displays the MAC authentication configuration for a specific interface.
stack-unit id
Displays the MAC authentication configuration for a specific stack unit.
Modes

User EXEC configuration mode

The show mac-authentication configuration command displays the following information.

Output field Description
Status Displays if MAC authentication is enabled or disabled
Auth-order The authentication order enabled on the device
Default VLAN The default VLAN specified on the device
Restricted VLAN The restricted VLAN specified on the device
Critical VLAN The critical VLAN specified on the device
Action on Auth failure The action to be taken on authentication failure
MAC Session Aging The status of the MAC session aging
Filter Strict Security The status of filter strict security
Re-authentication The status of re-authentication
Dot1x Override The status of dot1x override
Password Override The status of password override
Password Format The configured password format
Reauth-period The re-authentication period specified in seconds
Session max sw-age The maximum software age configured on the device
Session max hw-age The maximum hardware age configured on the device

The show mac-authentication configuration all | ethernet unit/slot/port command displays the following information.

Output field Description
Auth Order Displays the authentication order
Action on Auth failure Displays the action to be taken on authentication failure
Action on Auth timeout Displays the action to be taken on authentication timeout
Filter Strict Security Displays if filter strict security is enabled or disabled
DoS Protection Displays if DoS protection is enabled or disabled
Source-guard Protection Displays if Source-Guard Protection is enabled or disabled
Aging Displays if aging is enabled or disabled
Max-sessions Displays the count of the maximum sessions
Ingress-filtering Displays if ingress filtering is enabled or disabled
Examples

The following example displays the system level MAC authentication configuration.

device# show mac-authentication configuration 

Status : Enabled
Auth Order : dot1x mac-auth
Default VLAN : 4
Restricted VLAN : Not configured
Critical VLAN : Not configured
Action on Auth failure : Block traffic
MAC Session Aging : Enabled
Filter Strict Security : Enabled
Re-authentication : Enabled
Dot1x Override : Disabled
Password Override : Disabled
Password Format : xxxx.xxxx.xxxx
Reauth-period : 600 seconds
Session max sw-age : 120 seconds
Session max hw-age : 70 seconds

The following example displays the MAC authentication configuration for port 1/1/15.

device# configure terminal
device(config)# show mac-authentication configuration 1/1/15

Port 1/1/15 Configuration: 
Auth Order                     : dot1x mac-auth
Action on Auth failure         : Block traffic
Action on Auth timeout         : Treat as a failed authentication
Filter Strict Security         : Enabled
DoS Protection                 : Disabled (limit = 512)
Source-guard Protection        : Disabled
Aging                          : Enabled
Max-sessions                   : 32
Auth Filter List (Filter/VLAN) : 1/2 

The following example displays the MAC authentication information on all interfaces.

device# configure terminal
device(config)# show mac-authentication configuration all

Port 1/1/1 Configuration:
Auth Order                     : dot1x mac-auth
Action on Auth failure         : Block traffic
Action on Auth timeout         : Treat as a failed authentication
Filter Strict Security         : Enabled
DoS Protection                 : Disabled (limit = 512)
Source-guard Protection        : Disabled
Reauth-timeout                 : 60 seconds
Aging                          : Enabled
Max-sessions                   : 2

Port 1/1/3 Configuration:
Auth Order                     : dot1x mac-auth
Action on Auth failure         : Block traffic
Action on Auth timeout         : Treat as a failed authentication
Filter Strict Security         : Enabled
DoS Protection                 : Disabled (limit = 512)
Source-guard Protection        : Disabled
Reauth-timeout                 : 60 seconds
Aging                          : Enabled
Max-sessions                   : 2

History
Release version Command history
08.0.20 This command was introduced.
08.0.70 The command was modified to include the stack-unit id option.