Cisco NME-16ES-1G User Guide - Page 159

aaa authentication dot1x - default p password

Page 159 highlights

16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series aaa authentication dot1x aaa authentication dot1x To specify one or more authentication, authorization, and accounting (AAA) methods for use on interfaces running IEEE 802.1x, use the aaa authentication dot1x command in global configuration mode. To disable authentication, use the no form of this command. aaa authentication dot1x {default | listname} method1 [method2...] no aaa authentication dot1x {default | listname} method1 [method2...] Syntax Description default listname method1 [method2...] Uses the listed authentication methods that follow this argument as the default list of methods when a user logs in. Character string used to name the list of authentication methods tried when a user logs in. At least one of these keywords: • enable-Uses the enable password for authentication. • group radius-Uses the list of all Remote Authentication Dial-In User Service (RADIUS) servers for authentication. • line-Uses the line password for authentication. • local-Uses the local username database for authentication. • local-case-Uses the case-sensitive local username database for authentication. • none-Uses no authentication. The client is automatically authenticated by the switch without using the information supplied by the client. Defaults No authentication is performed. Command Modes Global configuration Command History Release 12.1(6)EA2 12.2(15)ZJ Modification This command was introduced. This command was implemented on the following platforms: Cisco 2600 series, Cisco 3600 series, and Cisco 3700 series routers. Usage Guidelines The method argument identifies the list of methods that the authentication algorithm tries in the given sequence to validate the password provided by the client. The only method that is truly 802.1x-compliant is the group radius method, in which the client data is validated against a RADIUS authentication server. The remaining methods enable AAA to authenticate the client by using locally configured data. For example, the local and local-case methods use the username and password that are saved in the Cisco IOS configuration file. The enable and line methods use the enable and line passwords for authentication. Cisco IOS Release 12.2(2)XT, 12.2(8)T, and 12.2(15)ZJ 159

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246

16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series
aaa authentication dot1x
159
Cisco IOS Release 12.2(2)XT, 12.2(8)T, and 12.2(15)ZJ
aaa authentication dot1x
To specify one or more authentication, authorization, and accounting (AAA) methods for use on
interfaces running IEEE 802.1x, use the
aaa authentication dot1x
command in global configuration
mode. To disable authentication, use the
no
form of this command.
aaa authentication dot1x
{
default
|
listname
}
method1
[
method2
...]
no aaa authentication dot1x
{
default
|
listname
}
method1
[
method2
...]
Syntax Description
Defaults
No authentication is performed.
Command Modes
Global configuration
Command History
Usage Guidelines
The
method
argument identifies the list of methods that the authentication algorithm tries in the given
sequence to validate the password provided by the client. The only method that is truly 802.1x-compliant
is the
group radius
method, in which the client data is validated against a RADIUS authentication
server. The remaining methods enable AAA to authenticate the client by using locally configured data.
For example, the
local
and
local-case
methods use the username and password that are saved in the Cisco
IOS configuration file. The
enable
and
line
methods use the
enable
and
line
passwords for
authentication.
default
Uses the listed authentication methods that follow this argument as the default
list of methods when a user logs in.
listname
Character string used to name the list of authentication methods tried when a
user logs in.
method1
[
method2
...]
At least one of these keywords:
enable
—Uses the enable password for authentication.
group radius
—Uses the list of all Remote Authentication Dial-In User
Service (RADIUS) servers for authentication.
line—
Uses the line password for authentication.
local—
Uses the local username database for authentication.
local-case—
Uses the case-sensitive local username database for
authentication.
none—
Uses no authentication. The client is automatically authenticated by
the switch without using the information supplied by the client.
Release
Modification
12.1(6)EA2
This command was introduced.
12.2(15)ZJ
This command was implemented on the following platforms: Cisco 2600
series, Cisco 3600 series, and Cisco 3700 series routers.