Configuring Flexible Authentication on an Interface

The following steps configure Flexible authentication at the interface level.

Note: Configuration at the interface level overrides related configuration at the global level. The global configuration is still applicable to other ports that do not have a per-port configuration. Refer to Configuring Flexible authentication globally for more information.

  1. Enter the configure terminal command to enter global configuration mode.
    device# configure terminal
  2. Enter the interface ethernet command to enter interface configuration mode.
    device(config)# interface ethernet 1/1/1
  3. (Optional) Enter the authentication auth-order mac-auth dot1x command to change the sequence of authentication to MAC authentication followed by IEEE 802.1X authentication if required.
    device(config-if-e1000-1/1/1)# authentication auth-order mac-auth dot1x
  4. Enter the authentication auth-default-vlan command to configure the authentication default VLAN (auth-default VLAN).
    Note: Ports that are members of the auth-default VLAN cannot be enabled for Flexible authentication. Likewise, ports that are enabled for Flexible authentication cannot be added manually to the auth-default VLAN.
    Note: Create the VLAN you plan to use before configuring it as the auth-default VLAN.
    device(config-if-e1000-1/1/1)# authentication auth-default-vlan 30
  5. (Optional) Enter the authentication auth-mode command to enable the multiple untagged mode on a specific Flexible authentication-enabled port and allow it to be a member of multiple untagged VLANs.
    device(config-if-e1000-1/1/1)# authentication auth-mode multiple-untagged
  6. (Optional) Enter the authentication mac-authentication lldp-override command to replace the authenticated MAC address on the FlexAuth port with the MAC address from the received LLDP frame.
    device(config-if-e1000-1/1/1)# auth auth-mode multiple-hosts
    device(config-if-e1000-1/1/1)# authentication mac-authentication lldp-override
    Note: The authentication mac-authentication lldp-override command can only be configured only when interface is operating in multiple-hosts mode. The value given for the timeout in interface level takes precedence over the timeout in global level.
  7. (Optional) Enter the authentication mac-authentication lldp-override timeout command to specify the wait time for the LLDP frame to arrive after authentication of first MAC address.
    device(config-if-e1000-1/1/1)# authentication mac-authentication lldp-override timeout 90 
    Note: By default, the LLDP override timeout (which is the wait time for the LLDP frame to arrive after authentication of first MAC address) is set to 30 seconds. If timeout value is not specified, this default value is automatically applied. It can be configured up to 120 seconds using the authentication mac-authentication lldp-override timeout command. The authentication mac-authentication lldp-override command can only be configured when auth auth-mode multiple-hosts command is enabled at the interface level. When the auth-mode multiple-hosts command is disabled at the interface level or mac-authentication lldp-override command is disabled globally, this command will also be removed from the interface level.
  8. (Optional) Enter the authentication disable-aging permitted-mac-only or the authentication disable-aging denied-mac-only command to prevent the permitted or denied MAC sessions from being aged out from a port.
    device(config-if-e1000-1/1/1)# authentication disable-aging permitted-mac-only
  9. (Optional) Enter the authentication max-sessions command to specify the maximum limit of authenticated MAC sessions on an interface.
    device(config-if-e1000-1/1/1)# authentication max-sessions 32
  10. (Optional) Enter the authentication dos-protection command to enable Denial of Service (DoS) authentication protection on an interface.
    device(config-if-e1000-1/1/1)# authentication dos-protection mac-limit 256
    Note: You can also configure the RUCKUS ICX device to limit the rate of authentication attempts sent to the RADIUS server.
  11. (Optional) Enter the authentication source-guard-protection command to enable IP Source Guard Protection along with authentication on an interface.
    device(config-if-e1000-1/1/1)# authentication source-guard-protection enable
  12. (Optional) Enter the authentication voice-vlan command to specify the voice VLAN to be used to add the port as tagged in the voice VLAN when it is not provided by the RADIUS server and when the clients are non-authenticated for various reasons, such as auth-failure and auth-timeout.
    device(config-if-e1000-1/1/1)# authentication voice-vlan 300
  13. (Optional) Enter the authentication allow-tagged command to allow tagged packet processing when the port is not tagged, which may be the case when multiple VMs are connected to the port so that they can be authenticated with MAC authentication, and automatic tagging of the port helps. This option is disabled by default.
    device(config-if-e1000-1/1/1)# authentication allow-tagged
  14. (Optional) Enter the authentication filter command to set up IEEE 802.1X authentication override. On the same line, enter a permit statement with the appropriate MAC address and mask so that the MAC addresses specified do not go through authentication.
    device(config-if-e1000-1/1/1)# authentication filter permit 0001.1234.1234 ffff.ffff.ffff 10
    The source MAC addresses defined using the authentication filter command are considered pre-authenticated and are not subject to authentication. A client can be authenticated in an untagged VLAN or tagged VLAN using the authentication filter. If the authentication filter has a tagged VLAN configuration, the clients are authenticated in the auth-default VLAN and the tagged VLAN provided in the authentication filter statement (VLAN ID 10 in the previous example). The clients authorized in the auth-default VLAN allow both untagged and tagged traffic.