Configuring Security
Configuring 802. 1 X
Cisco 220 Series Smart Switches Administration Guide Release 1.1.0.x
•
Guest VLAN—Select the guest VLAN from the list of VLANs.
-
Selected—Enables using a Guest VLAN for unauthorized ports. If a Guest
VLAN is enabled, the unauthorized port automatically joins the VLAN
selected in the Guest VLAN IDfield in the 802.1X Port Authentication
page. After an authentication failure, and ifGuest VLAN is activated
globally on a given port, the guest VLAN is automatically assigned to the
unauthorized ports as an Untagged VLAN.
-
Cleared—Disables Guest VLAN on the port.
•
Periodic Reauthentication—Select to enable port re-authentication
attempts after the specified Reauthentication Period.
•
Reauthentication Period—Enter the number of seconds after which the
selected port is reauthenticated.
•
Reauthenticate Now—Select to enable immediate port re-authentication.
•
Authenticator State—Displays the defined port authorization state.
If the port is not in Force-Authorized or Force-Unauthorized, it is in Auto
NOTE
Mode and the authenticator displays the state of the authentication in progress.
After the port is authenticated, the state is shown as Authenticated.
•
Max Hosts—Enter the number of maximum of authenticated hosts allowed
on the specific interface. This value only takes effect on multi-sessions
mode.
•
Quiet Period—Enter the number of seconds that the switch remains in the
quiet state following a failed authentication exchange.
•
Resending EAP—Enter the number of seconds that the switch waits for a
response to an Extensible Authentication Protocol (EAP) request/identity
frame from the supplicant (client) before resending the request.
•
Max EAP Requests—Enter the maximum number of EAP requests that can
be sent. If a response is not received after the defined period (supplicant
timeout), the authentication process is restarted.
•
Supplicant Timeout-—Enter the number of seconds that lapses before EAP
requests are resent to the supplicant.
•
Server Timeout—Enter the number of seconds that lapses before the switch
resends a request to the authentication server.
16
211