Displaying the 802.1X authentication sessions
Use the
show dot1x sessions command to view details of the 802.1X authentication sessions, such as the ports,
MAC addresses, IP addresses, VLANs, and so on.
Note: The IP address of the authenticated host is displayed only if an IP ACL is applied
to the interface based on the RADIUS server response.
The following example displays 802.1X sessions for all interfaces.
device(config)# show dot1x sessions all
---------------------------------------------------------------------------------------------------------
Port MAC IP(v4/v6) User VLAN Auth ACL Session Age PAE
Addr Addr Name State Time State
---------------------------------------------------------------------------------------------------------
2/1/25 00aa.aaaa.0000 fe80::2aa:aaff:feaa: VDI_1 130 permit Yes 210 Ena AUTHENTICATED
2000::2
2000::4
2/1/25 00aa.aaaa.0001 fe80::2aa:aaff:feaa: VDI_2 130 permit Yes 210 Ena AUTHENTICATED
3000::2
3000::2
The following example displays 802.1X sessions for a specific interface.
device(config)# show dot1x sessions ethernet 2/1/1
---------------------------------------------------------------------------------------------
Port MAC IP User Vlan Auth ACL Session Age PAE
Addr Addr Name State Time State
---------------------------------------------------------------------------------------------
2/1/1 0010.9400.1303 192.85.1.2 User1 200 permit Yes 100 Ena AUTHENTICATED
The following example displays a brief description of 802.1X sessions.
device# show dot1x sessions brief
----------------------------------------------------------------------------
Port Number of Number of Number of Untagged Dynamic Dynamic
Attempted Authorized Denied VLAN Type Port ACL MAC-Filt
Users Users Users
-----------------------------------------------------------------------------
1/1/2 1 1 0 Radius-VLAN No No
1/1/3 0 0 0 Auth-Default-VLAN No No
1/1/4 0 0 0 Auth-Default-VLAN No No
1/1/5 0 0 0 Auth-Default-VLAN No No
2/1/1 0 0 0 Auth-Default-VLAN No No
2/1/2 0 0 0 Auth-Default-VLAN No No
2/1/4 0 0 0 Auth-Default-VLAN No No