show dot1x sessions

Displays 802.1X authentication sessions at the global and interface levels.
Syntax
show dot1x sessions { all | brief | stack-unit id | ethernet unit/slot/port }
Parameters
all
Displays of 802.1X authentication sessions for all ports.
brief
Displays summary information for 802.1X authentication sessions.
ethernet unit/slot/port
Displays 802.1X authentication sessions for a specified Ethernet interface.
stack-unit id
Displays of 802.1X authentication sessions for the specified stack unit.
Modes

Privileged EXEC mode

Usage Guidelines

A client session can have an IPv4 address and multiple IPv6 addresses. When multiple addresses exist, the show dot1x sessions command displays all addresses for the session.

The show dot1x sessions command displays the following information.

Output field Description
Port Port number.
MAC Addr MAC address of the client.
IP Addr IP address or addresses of the client (a session can have an IPv4 address and multiple IPv6 addresses). IP addresses of the authenticated host are only displayed when an IP ACL is applied to the interface based on the RADIUS server response.
User Name User name.
Vlan VLAN ID.
Auth State Authentication state.
ACL Specific applied ACL.
Session Time Session time.
Age Age of the session.
PAE State Port access entity state.
Examples

The following example displays 802.1X sessions for all interfaces.

device(config)# show dot1x sessions all
---------------------------------------------------------------------------------------------------------
Port    MAC             IP(v4/v6)            User    VLAN  Auth    ACL  Session Age PAE
        Addr            Addr                 Name          State        Time        State
---------------------------------------------------------------------------------------------------------
2/1/25  00aa.aaaa.0000  fe80::2aa:aaff:feaa: VDI_1   130   permit  Yes  210     Ena AUTHENTICATED
                        2000::2
                        2000::4
2/1/25  00aa.aaaa.0001  fe80::2aa:aaff:feaa: VDI_2   130   permit  Yes  210     Ena AUTHENTICATED
                        3000::2
                        3000::2

The following example displays 802.1X authentication sessions for a specific interface.

device(config)# show dot1x sessions ethernet 2/1/1
---------------------------------------------------------------------------------------------
Port   MAC             IP          User    Vlan  Auth    ACL    Session   Age   PAE
       Addr            Addr        Name          State          Time            State
---------------------------------------------------------------------------------------------
2/1/1  0010.9400.1303  192.85.1.2   User1  200   permit  Yes    100       Ena   AUTHENTICATED

The following example displays 802.1X authentication sessions in brief.

device# show dot1x sessions brief
----------------------------------------------------------------------------
Port   Number of  Number of   Number of   Untagged           Dynamic   Dynamic
       Attempted  Authorized  Denied      VLAN Type          Port ACL  MAC-Filt 
       Users      Users       Users
-----------------------------------------------------------------------------
1/1/2  1          1           0           Radius-VLAN        No       No
1/1/3  0          0           0           Auth-Default-VLAN  No       No
1/1/4  0          0           0           Auth-Default-VLAN  No       No
1/1/5  0          0           0           Auth-Default-VLAN  No       No
2/1/1  0          0           0           Auth-Default-VLAN  No       No
2/1/2  0          0           0           Auth-Default-VLAN  No       No
2/1/4  0          0           0           Auth-Default-VLAN  No       No
History
Release version Command history
08.0.20 This command was introduced.
08.0.50 The command output was updated.
08.0.61 The command output was modified to display multiple IPv6 addresses for a session.
08.0.70 The command was modified to include the stack-unit id option.