802.1X | 129
3 (Optional) Use MAB authentication only—
do not use 802.1X authentication first. If
MAB fails the port or the MAC address is
blocked, the port is placed in the guest
VLAN (if configured). 802.1x
authentication is not even attempted.
Re-authentication is performed using
802.1X timers.
dot1x auth-type mab-only INTERFACE
4
Display the 802.1X and MAB configuration.
show dot1x interface
EXEC Privilege
FTOS#show dot1x int Gi 2/32
802.1X information on Gi 2/32:
-----------------------------
Dot1x Status:Enable
Port Control:AUTO
Port Auth Status:UNAUTHORIZED
Re-Authentication:Disable
Untagged VLAN id:None
Guest VLAN:Enable
Guest VLAN id:10
Auth-Fail VLAN:Enable
Auth-Fail VLAN id:11
Auth-Fail Max-Attempts:3
Mac-Auth-Bypass:Enable
Tx Period:30 seconds
Quiet Period:60 seconds
ReAuth Max:2
Supplicant Timeout:30 seconds
Server Timeout:30 seconds
Re-Auth Interval:3600 seconds
Max-EAP-Req:2
Auth Type:SINGLE_HOST
Auth PAE State:Initialize
Backend State:Initialize
Step Task Command Syntax Command Mode