Configuring Flexible Authentication on an Interface
The following steps configure Flexible authentication at the interface level.
Note: Configuration at the interface level overrides related configuration at the global
level. The global configuration is still applicable to other ports that do not have
a per-port configuration. Refer to
Configuring Flexible authentication globally for more information.
- Enter the
configure terminalcommand to enter global configuration mode. - Enter the
interface ethernetcommand to enter interface configuration mode. - (Optional) Enter the
authentication auth-order mac-auth dot1xcommand to change the sequence of authentication to MAC authentication followed by 802.1X authentication if required. - Enter the
authentication auth-default-vlancommand to configure the authentication default VLAN (auth-default VLAN).Note: Ports that are members of the auth-default VLAN cannot be enabled for Flexible authentication. Likewise, ports that are enabled for Flexible authentication cannot be added manually to the auth-default VLAN.Note: Create the VLAN you plan to use before configuring it as the auth-default VLAN. - (Optional) Enter the
authentication fail-actioncommand, followed by the desired authentication failure action.- Enter the
restricted-vlan keyword, followed by the VLAN ID,
to move the port to the restricted VLAN after authentication failure.
device(config-if-e1000-1/1/1)# authentication fail-action restricted-vlan 4
- Enter the permit keyword
to log the failed authentication and move the port to the
auth-default-VLAN.
device(config-if-e1000-1/1/1)# authentication fail-action permit
Note: In single untagged mode with the authentication fail-action configured as "permit", successfully authenticated client ports are placed in the RADIUS-specified VLAN or the auth-default-vlan. The subsequent failed clients are also placed in the previously authenticated user's VLAN. - Enter the
restricted-vlan keyword, followed by the VLAN ID,
to move the port to the restricted VLAN after authentication failure.
- (Optional) Enter the
authentication auth-modecommand to enable the multiple untagged mode on a specific Flexible authentication-enabled port and allow it to be a member of multiple untagged VLANs. - (Optional) Enter the
authentication disable-aging permitted-mac-onlyor theauthentication disable-aging denied-mac-onlycommand to prevent the permitted or denied MAC sessions from being aged out from a port. - (Optional) Enter the
authentication max-sessionscommand to specify the maximum limit of authenticated MAC sessions on an interface. - (Optional) Enter the
authentication dos-protectioncommand to enable Denial of Service (DoS) authentication protection on an interface. - (Optional) Enter the
authentication source-guard-protectioncommand to enable IP Source Guard Protection along with authentication on an interface. - (Optional) Enter the
authentication voice-vlancommand to specify the voice VLAN to be used to add the port as tagged in the voice VLAN when it is not provided by the RADIUS server and when the clients are non-authenticated for various reasons, such as auth-failure and auth-timeout. - (Optional) Enter the
authentication allow-taggedcommand to allow tagged packet processing when the port is not tagged, which may be the case when multiple VMs are connected to the port so that they can be authenticated with MAC authentication, and automatic tagging of the port helps. This option is disabled by default. - (Optional) Enter the
authentication filtercommand to set up 802.1X authentication override. On the same line, enter a permit statement with the appropriate MAC address and mask so that the MAC addresses specified do not go through authentication.The source MAC addresses defined using theauthentication filtercommand are considered pre-authenticated and are not subject to authentication. A client can be authenticated in an untagged VLAN or tagged VLAN using the authentication filter. If the authentication filter has a tagged VLAN configuration, the clients are authenticated in the auth-default VLAN and the tagged VLAN provided in the authentication filter statement (VLAN ID 10 in the previous example). The clients authorized in the auth-default VLAN allow both untagged and tagged traffic.