8
Configuring Port-Based Access Control
(802.1x)
Contents
Overview . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-2
How 802.1x Operates . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-5
Terminology . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-7
General Operating Rules and Notes . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-9
General Setup Procedure for Port-Based Access Control
(802.1x) . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-11
Configuring Switch Ports as 802.1x Authenticators . . . . . . . . . . . . 8-14
802.1x Open VLAN Mode . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-20
Option For Authenticator Ports: Configure Port-Security
To Allow Only 802.1x Devices . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 8-31
Configuring Switch Ports To Operate As Supplicants for
802.1x Connections to Other Switches . . . . . . . . . . . . . . . . . . . . . . . . 8-33
Displaying 802.1x Configuration, Statistics, and Counters . . . . . . 8-37
How RADIUS/802.1x Authentication Affects VLAN Operation . . 8-43
Messages Related to 802.1x Operation . . . . . . . . . . . . . . . . . . . . . . . . 8-47
8-1