ii
EAP relay ································································································································································ 67
EAP termination ····················································································································································· 69
Configuring 802.1X ·················································································································································· 71
Access control methods ················································································································································· 71
802.1X VLAN manipulation ········································································································································· 71
Authorization VLAN ·············································································································································· 71
Guest VLAN ··························································································································································· 73
Auth-Fail VLAN ······················································································································································ 74
Critical VLAN ························································································································································· 76
Using 802.1X authentication with other features ······································································································· 77
ACL assignment ····················································································································································· 77
User profile assignment ········································································································································ 78
EAD assistant ························································································································································· 78
Configuration prerequisites ··········································································································································· 79
802.1X configuration task list ······································································································································· 79
Enabling 802.1X ···························································································································································· 79
Enabling EAP relay or EAP termination ······················································································································· 80
Setting the port authorization state ······························································································································ 81
Specifying an access control method ·························································································································· 81
Setting the maximum number of concurrent 802.1X users on a port ······································································· 81
Setting the maximum number of authentication request attempts ············································································· 82
Setting the 802.1X authentication timeout timers ······································································································· 82
Configuring the online user handshake feature ·········································································································· 83
Configuration guidelines ······································································································································ 83
Configuration procedure ······································································································································ 83
Configuring the authentication trigger feature ············································································································ 83
Configuration guidelines ······································································································································ 84
Configuration procedure ······································································································································ 84
Specifying a mandatory authentication domain on a port ························································································ 84
Configuring the quiet timer ··········································································································································· 85
Enabling the periodic online user reauthentication feature ······················································································· 85
Configuring an 802.1X guest VLAN ··························································································································· 86
Configuration guidelines ······································································································································ 86
Configuration prerequisites ·································································································································· 86
Configuration procedure ······································································································································ 87
Configuring an 802.1X Auth-Fail VLAN ······················································································································ 87
Configuration guidelines ······································································································································ 87
Configuration prerequisites ·································································································································· 87
Configuration procedure ······································································································································ 88
Configuring an 802.1X critical VLAN ························································································································· 88
Configuration guidelines ······································································································································ 88
Configuration prerequisites ·································································································································· 88
Configuration procedure ······································································································································ 88
Specifying supported domain name delimiters ··········································································································· 89
Configuring the EAD assistant feature ························································································································· 89
Displaying and maintaining 802.1X ··························································································································· 90
802.1X authentication configuration examples ·········································································································· 90
Basic 802.1X authentication configuration example ························································································ 90
802.1X guest VLAN and authorization VLAN configuration example ··························································· 93
802.1X with ACL assignment configuration example ······················································································· 95
802.1X with EAD assistant configuration example ··························································································· 97
Troubleshooting 802.1X EAD assistant for Web browser users ············································································· 100