show dot1x configuration

Displays detailed information about the 802.1X configuration.
Syntax
show dot1x configuration[ all | stack-unit id | ethernet unit/slot/port ]
Parameters
all
Displays information about the 802.1X configuration on all ports.
ethernet unit/slot/port
Displays information about the 802.1X configuration on a specific port.
stack-unit id
Displays 802.1X configuration for the specified stack unit.
Modes

User EXEC mode

Privileged EXEC mode

Global configuration mode

Interface configuration mode

dot1x configuration mode

The show dot1x configuration command displays the following information:

Output field Description
PAE Capability The Port Access Entity (PAE) role for the RUCKUS device. This is always "Authenticator Only".
system-auth-control Whether system authentication control is enabled on the device. The dot1x-enable command enables system authentication control on the device.
Number of Ports enabled The number of ports on which 802.1X authentication is enabled.
Re-authentication Whether periodic re-authentication is enabled on the device. When periodic re-authentication is enabled, the device automatically re-authenticates clients every 3,600 seconds by default.
Authentication-fail-action The configured authentication-failure action. This can be Restricted VLAN or Block Traffic.
Mac Session Aging Whether aging for dot1x-MAC-sessions has been enabled or disabled for permitted or denied dot1x-MAC-sessions.
Mac Session max-age The configured software aging time for dot1x-MAC-sessions.
Protocol Version The version of the 802.1X protocol in use on the device.
quiet-period When the device is unable to authenticate a client, the amount of time the device waits before trying again (default 60 seconds).
tx-period When a client does not send back an EAP-response/identity frame, the amount of time the device waits before retransmitting the EAP-request/identity frame to a client (default 30 seconds).
supptimeout When a client does not respond to an EAP-request frame, the amount of time before the device retransmits the frame.
servertimeout When the Authentication Server does not respond to a message sent from the client, the amount of time before the device retransmits the message.
maxreq The number of times the device retransmits an EAP-request/identity frame if it does not receive an EAP-response/identity frame from a client (default 2 times).
reAuthmax The maximum number of re-authentication attempts.
re-authperiod How often the device automatically re-authenticates clients when periodic re-authentication is enabled (default 3,600 seconds).
global strict security Whether strict security mode is enabled or disabled globally.

The show dot1x configuration ethernet slot/port command displays the following information:

Output field Description
Port-Control The configured port control type for the interface. This can be one of the following types:
  • force-authorized: The controlled port is placed unconditionally in the authorized state, allowing all traffic. This is the default state for ports on the device.
  • force-unauthorized: The controlled port is placed unconditionally in the unauthorized state. No authentication takes place for any connected 802.1X clients.
  • auto - The authentication status for each 802.1X client depends on the authentication status returned from the RADIUS server.
filter strict security Whether strict security mode is enabled or disabled on the interface.
Action on RADIUS timeout The action taken for the client MAC session on this port upon a RADIUS timeout.
Authentication-fail-action The configured authentication-failure action. This can be Restricted VLAN or Block Traffic.
PVID State The port default VLAN ID (PVID) and the state of the port PVID. The PVID state can be one of the following:
  • Normal - The port PVID is not set by a RADIUS server, nor is it the restricted VLAN.
  • RADIUS - The port PVID was dynamically assigned by a RADIUS server.
  • RESTRICTED - The port PVID is the restricted VLAN.
Original PVID The originally configured (not dynamically assigned) PVID for the port.
Authorized PVID ref count The number of authenticated MAC sessions on this port’s current PVID (port default VLAN ID).
Restricted PVID ref count The number of MAC sessions on the port that failed authentication and are now in the restricted VLAN (which should be the port’s current PVID).
Radius assign PVID ref count The number of times the port has changed PVIDs due to RADIUS VLAN assignment.
num mac sessions The number of dot1x-MAC-sessions on the port.
num mac authorized The number of authorized dot1x-MAC-sessions on the port.
num Dynamic Tagged Vlan The number of dynamically tagged VLANs on the port.
Number of Auth filter The number of dynamic MAC filters applied to the port.
Examples

The following example displays information about the 802.1X configuration.

device# show dot1x configuration
PAE Capability                : Authenticator Only
system-auth-control           : Enable
Number of Ports enabled       : 3
Re-Authentication             : Disabled
Authentication-fail-action    : Per Port
Mac Session Aging             : Enabled
Mac Session max-age           : 120 seconds
Protocol Version              : 1
quiet-period                  : 60 Seconds
tx-period                     : 30 Seconds
supptimeout                   : 30 Seconds
servertimeout                 : 30 Seconds
maxreq                        : 2
reAuthmax                     : 2
re-authperiod                 : 3600 Seconds
global strict security        : Enable

The following example displays information about the 802.1X configuration on an individual port.

device# show dot1x configuration ethernet 4/1/12
Port-Control                  : control-auto
filter strict security        : Enable
Action on RADIUS timeout      : Restart authentication
Authentication-fail-action    : Restricted VLAN(299)
PVID State                    : Normal (1)
Original PVID                 : 1
Authorized PVID ref count     : 2
Restricted PVID ref count     : 0
Radius assign PVID ref count  : 0
num mac sessions              : 2
num mac authorized            : 2
num Dynamic Tagged Vlan       : 0
Number of Auth filter         : 0
History
Release version Command history
08.0.70 The command was modified to include the stack-unit id option.