Cisco Systems 4500 Switch User Manual


  Open as PDF
of 1504
 
40-72
Software Configuration Guide—Release 15.0(2)SG
OL-23818-01
Chapter 40 Configuring 802.1X Port-Based Authentication
Configuring 802.1X Port-Based Authentication
To enable 802.1X with VLAN assignment, perform this task:
The following example shows how to configure MDA on an interface and 802.1X as the authentication
mechanism:
Switch(config)# interface FastEthernet3/3
Switch(config-if)# switchport access vlan 10
Switch(config-if)# switchport mode access
Switch(config-if)# switchport voice vlan 16
Switch(config-if)# authentication host-mode multi-domain
Switch(config-if)# authentication port-control auto
Switch(config-if)# dot1x pae authenticator
Switch(config-if)# end
Note You must configure VLAN assignment in the ACS server. No configuration changes are required
on the switch.
Cisco ACS Configuration for VLAN Assignment
The procedure for enabling MDA with voice VLAN assignment is the same as that for activating MDA
except for one step: Configure a VLAN for dynamic VLAN assignment after selecting
User > IETF RADIUS Attributes (Figure 40-16). This step ensures correct functioning of the ACS
configuration required for dynamic VLAN assignment.
Command Purpose
Step 1
Switch# configure terminal
Enters global configuration mode.
Step 2
Switch(config)# interface
interface-id
Enters interface configuration mode.
Step 3
Switch(config-if)# switchport
access vlan-id
Sets the VLAN for a switched interface in access mode.
Step 4
Switch(config-if)# switchport mode
access
Specifies a nontrunking, nontagged single VLAN Layer 2 interface.
Step 5
Switch(config-if)# switchport voice
vlan vlan-id
Sets the voice VLAN for the interface.
Step 6
Switch(config-if)# authentication
host-mode multi-domain
Enables MDA on the interface.
Step 7
Switch(config-if)# authentication
port-control auto
Enables 802.1X authentication on the interface.
Step 8
Switch(config-if)# dot1x pae
authenticator
Enables 802.1X authentication on the port with default parameters.
Refer to the “Default 802.1X Configuration” section on page 40-27.
Step 9
Switch(config)# end
Returns to privileged EXEC mode.
Step 10
Switch# show dot1x interface
interface-id details
(Optional) Verifies your entries.
Step 11
Switch# copy running-config
startup-config
(Optional) Saves your entries in the configuration file.