Enabling 802.1X Authentication
The following steps are for enabling and activating 802.1X authentication and for
configuring certain 802.1X-specific commands.
- Enter the
configure terminalcommand to enter global configuration mode. - Enter the
authenticationcommand to enter authentication mode. - Enter the
dot1x enablecommand to enable 802.1X authentication.Note: Ports that are members of the auth-default VLAN cannot be enabled for Flexible authentication. Likewise, ports that are enabled for Flexible authentication cannot be added manually to the auth-default VLAN. - Enter the
dot1x enable{ all | ethernet unit/slot/port [ to unit/slot/port ] } command to enable 802.1X authentication on all interfaces, a single interface, or a specific set of interfaces. - Enter the
dot1x port-control autocommand to set the controlled port in the unauthorized state until authentication takes place between the client and the authentication server.The following example configures the command globally.The following example configures the command on a single interface. (Interface configuration overrides global configuration if they differ.)Once the client passes authentication, the port becomes authorized. This activates authentication on an 802.1X-enabled interface. The controlled port remains in the authorized state until the client logs off. - (Optional) Enter the
dot1x guest-vlancommand to configure the VLAN into which the port should be placed when the client's response to the dot1x requests for authentication times out. - (Optional) Configure the timeout parameters that determine the time interval for client
reauthentication and EAP retransmissions using the following commands:
- Enter the
dot1x timeout quiet-periodcommand to configure the amount of time the ICX device should wait before reauthenticating the client.device(config-authen)# dot1x timeout quiet-period 30
- Enter the
dot1x timeout tx-periodcommand to configure the amount of time the ICX device should wait before retransmitting EAP-Request/Identity frames to the client.device(config-authen)# dot1x timeout tx-period 30
- Enter the
dot1x timeout supplicantcommand to configure the amount of time the ICX device should wait before retransmitting RADIUS EAP-Request/Challenge frames to the client.device(config-authen)# dot1x timeout supplicant 30
Based on the timeout parameters, the client is reauthenticated, and EAP-Request/Identity frames and EAP-Request/Challenge frames are retransmitted. - Enter the
- (Optional) Enter the
dot1x max-reauth-reqcommand to configure the maximum number of times EAP-Request/Identity frames are sent for reauthentication after the first authentication attempt.If no EAP Response/Identity frame is received from the client after the specified number of EAP-Request/Identity frame retransmissions, the device restarts the authentication process with the client. - (Optional) Enter the
dot1x max-reqcommand to configure the maximum number of times EAP-Request/Challenge frames are retransmitted when an EAP Response/Identity frame is not received from the client. - (Optional) Enter the
dot1x macauth-overridecommand to configure the device to perform MAC authentication after 802.1X authentication, if 802.1X authentication fails for the clients.Note: This command is applicable only when the authentication sequence is configured as 802.1X authentication followed by MAC authentication.