Cisco NME-16ES-1G User Guide - Page 135

Enabling 802.1x Authentication Example, Configuring the Switch-to-RADIUS-Server Communication Example

Page 135 highlights

16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Configuration Examples for the 16- and 36-Port Ethernet Switch Module • Setting the Switch-to-Client Frame-Retransmission Number Example, page 135 • Enabling Multiple Hosts Example, page 135 Enabling 802.1x Authentication Example The following example shows how to enable AAA and 802.1x on Fast Ethernet port 0/1: Switch# configure terminal Switch(config)# aaa new-model Switch(config)# aaa authentication dot1x default group radius Switch(config)# interface fastethernet0/1 Switch(config-if)# dot1x port-control auto Switch(config-if)# end Configuring the Switch-to-RADIUS-Server Communication Example The following example shows how to specify the server with IP address 172.20.39.46 as the RADIUS server, to use port 1612 as the authorization port, and to set the encryption key to rad123, matching the key on the RADIUS server: Switch(config)# radius-server host 172.l20.39.46 auth-port 1612 key rad123 Enabling Periodic Re-Authentication Example The following example shows how to enable periodic reauthentication and set the number of seconds between reauthentication attempts to 4000: Switch(config)# dot1x re-authentication Switch(config)# dot1x timeout re-authperiod 4000 Changing the Quiet Period Example The following example shows how to set the quiet time on the switch to 30 seconds: Switch(config)# dot1x timeout quiet-period 30 Changing the Switch-to-Client Retransmission Time Example The following example shows how to set 60 seconds as the number of seconds that the switch waits for a response to an EAP-request/identity frame from the client before retransmitting the request: Switch(config)# dot1x timeout tx-period 60 Setting the Switch-to-Client Frame-Retransmission Number Example The following example shows how to set 5 as the number of times that the switch sends an EAP-request/identity request before restarting the authentication process: Switch(config)# dot1x max-req 5 Enabling Multiple Hosts Example The following example shows how to enable 802.1x on Fast Ethernet interface 0/1 and to allow multiple hosts: Cisco IOS Release 12.2(2)XT, 12.2(8)T, and 12.2(15)ZJ 135

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246

16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series
Configuration Examples for the 16- and 36-Port Ethernet Switch Module
135
Cisco IOS Release 12.2(2)XT, 12.2(8)T, and 12.2(15)ZJ
Setting the Switch-to-Client Frame-Retransmission Number Example, page 135
Enabling Multiple Hosts Example, page 135
Enabling 802.1x Authentication Example
The following example shows how to enable AAA and 802.1x on Fast Ethernet port 0/1:
Switch#
configure terminal
Switch(config)#
aaa new-model
Switch(config)#
aaa authentication dot1x default group radius
Switch(config)#
interface fastethernet0/1
Switch(config-if)#
dot1x port-control auto
Switch(config-if)#
end
Configuring the Switch-to-RADIUS-Server Communication Example
The following example shows how to specify the server with IP address 172.20.39.46 as the RADIUS
server, to use port 1612 as the authorization port, and to set the encryption key to rad123, matching the
key on the RADIUS server:
Switch(config)#
radius-server host 172.l20.39.46 auth-port 1612 key rad123
Enabling Periodic Re-Authentication Example
The following example shows how to enable periodic reauthentication and set the number of seconds
between reauthentication attempts to 4000:
Switch(config)#
dot1x re-authentication
Switch(config)#
dot1x timeout re-authperiod 4000
Changing the Quiet Period Example
The following example shows how to set the quiet time on the switch to 30 seconds:
Switch(config)#
dot1x timeout quiet-period 30
Changing the Switch-to-Client Retransmission Time Example
The following example shows how to set 60 seconds as the number of seconds that the switch waits for a
response to an EAP-request/identity frame from the client before retransmitting the request:
Switch(config)#
dot1x timeout tx-period 60
Setting the Switch-to-Client Frame-Retransmission Number Example
The following example shows how to set 5 as the number of times that the switch sends an
EAP-request/identity request before restarting the authentication process:
Switch(config)#
dot1x max-req 5
Enabling Multiple Hosts Example
The following example shows how to enable 802.1x on Fast Ethernet interface 0/1 and to allow multiple
hosts: