Chapter 9
Configuring IEEE 802.1x Port-Based Authentication
Figure 9-6
1
1
3
5
Guidelines
•
•
•
For more information, see the
section on page
Configuring 802.1x Authentication
These sections contain this configuration information:
•
•
•
•
•
•
•
•
OL-12247-04
Authenticator and Supplicant Switch using CISP
Workstations (clients)
Authenticator switch
Trunk port
You can configure NEAT ports with the same configurations as the other authentication ports. When
the supplicant switch authenticates, the port mode is changed from access to trunk based on the
switch vendor-specific attributes (VSAs). (
The VSA changes the authenticator switch port mode from access to trunk and enables 802.1x trunk
encapsulation and the access VLAN if any would be converted to a native trunk VLAN. VSA does
not change any of the port configurations on the supplicant
To change the host mode and the apply a standard port configuration on the authenticator switch
port, you can also use AutoSmart ports user-defined macros, instead of the switch VSA. This allows
you to remove unsupported configurations on the authenticator switch port and to change the port
mode from access to trunk. For more information, see
Macros".
9-58.
Default 802.1x Authentication Configuration, page 9-32
Configuring 802.1x Violation Modes, page 9-36
Cisco Catalyst Blade Switch 3130 and 3032 for Dell Software Configuration Guide
2
3
5
2
Supplicant switch (outside wiring closet)
4
Access control server (ACS)
device-traffic-class=switch).
"Configuring an Authenticator and a Supplicant Switch with NEAT"
(required)
(optional)
Configuring 802.1x Authentication
4
Chapter 12, "Configuring Smartports
(required)
9-31