10-23
Catalyst 3750 Switch Software Configuration Guide
OL-8550-02
Chapter 10 Configuring IEEE 802.1x Port-Based Authentication
Configuring IEEE 802.1x Authentication
IEEE 802.1x Authentication Configuration Guidelines
These section has configuration guidelines for these features:
• IEEE 802.1x Authentication, page 10-23
• VLAN Assignment, Guest VLAN, Restricted VLAN, and Inaccessible Authentication Bypass, page
10-24
• MAC Authentication Bypass, page 10-25
IEEE 802.1x Authentication
These are the IEEE 802.1x authentication configuration guidelines:
• When IEEE 802.1x authentication is enabled, ports are authenticated before any other Layer 2 or
Layer 3 features are enabled.
• If you try to change the mode of an IEEE 802.1x-enabled port (for example, from access to trunk),
an error message appears, and the port mode is not changed.
Re-authentication number 2 times (number of times that the switch restarts the
authentication process before the port changes to the
unauthorized state).
Quiet period 60 seconds (number of seconds that the switch remains in
the quiet state following a failed authentication exchange
with the client).
Retransmission time 30 seconds (number of seconds that the switch should
wait for a response to an EAP request/identity frame
from the client before resending the request).
Maximum retransmission number 2 times (number of times that the switch will send an
EAP-request/identity frame before restarting the
authentication process).
Client timeout period 30 seconds (when relaying a request from the
authentication server to the client, the amount of time the
switch waits for a response before resending the request
to the client.)
Authentication server timeout period 30 seconds (when relaying a response from the client to
the authentication server, the amount of time the switch
waits for a reply before resending the response to the
server. This setting is not configurable.)
Inactivity timeout Disabled.
Guest VLAN None specified.
Inaccessible authentication bypass Disabled.
Restricted VLAN None specified.
Authenticator (switch) mode None specified.
MAC authentication bypass Disabled.
Table 10-2 Default IEEE 802.1x Authentication Configuration (continued)
Feature Default Setting