Cisco NME-16ES-1G User Guide - Page 66

Enabling Multiple Hosts, Resetting the 802.1x Configuration to the Default Values, Displaying 802.1x

Page 66 highlights

Configuration Tasks 16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series Enabling Multiple Hosts You can attach multiple hosts to a single 802.1x-enabled port as shown in Figure 3 on page 12. In this mode, only one of the attached hosts must be successfully authorized for all hosts to be granted network access. If the port becomes unauthorized (reauthentication fails, and an EAPOL-logoff message is received), all attached clients are denied access to the network. Beginning in privileged EXEC mode, follow these steps to allow multiple hosts (clients) on an 802.1x-authorized port that has the dot1x port-control interface configuration command set to auto. Step 1 Step 2 Command configure terminal interface interface-id Step 3 dot1x multiple-hosts Step 4 Step 5 Step 6 end show dot1x interface interface-id copy running-config startup-config Purpose Enters global configuration mode. Enters interface configuration mode, and specify the interface to which multiple hosts are indirectly attached. Allows multiple hosts (clients) on an 802.1x-authorized port. Make sure that the dot1x port-control interface configuration command is set to auto for the specified interface. Returns to privileged EXEC mode. Verifies your entries. (Optional) Saves your entries in the configuration file. To disable multiple hosts on the port, use the no dot1x multiple-hosts interface configuration command. Resetting the 802.1x Configuration to the Default Values You can reset the 802.1x configuration to the default values with a single command. Beginning in privileged EXEC mode, follow these steps to reset the 802.1x configuration to the default values: Step 1 Step 2 Step 3 Step 4 Step 5 Command configure terminal dot1x default end show dot1x copy running-config startup-config Purpose Enters global configuration mode. Resets the configurable 802.1x parameters to the default values. Returns to privileged EXEC mode. Verifies your entries. (Optional) Saves your entries in the configuration file. Displaying 802.1x Statistics and Status To display 802.1x statistics for all interfaces, use the show dot1x statistics privileged EXEC command. To display 802.1x statistics for a specific interface, use the show dot1x statistics interface interface-id privileged EXEC command. To display the 802.1x administrative and operational status for the switch, use the show dot1x privileged EXEC command. To display the 802.1x administrative and operational status for a specific interface, use the show dot1x interface interface-id privileged EXEC command. Cisco IOS Release 12.2(2)XT, 12.2(8)T, and 12.2(15)ZJ 66

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246

16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series
Configuration Tasks
66
Cisco IOS Release 12.2(2)XT, 12.2(8)T, and 12.2(15)ZJ
Enabling Multiple Hosts
You can attach multiple hosts to a single 802.1x-enabled port as shown in
Figure 3 on page 12
. In this
mode, only one of the attached hosts must be successfully authorized for all hosts to be granted network
access. If the port becomes unauthorized (reauthentication fails, and an EAPOL-logoff message is
received), all attached clients are denied access to the network.
Beginning in privileged EXEC mode, follow these steps to allow multiple hosts (clients) on an
802.1x-authorized port that has the
dot1x port-control
interface configuration command set to
auto
.
To disable multiple hosts on the port, use the
no dot1x multiple-hosts
interface configuration command.
Resetting the 802.1x Configuration to the Default Values
You can reset the 802.1x configuration to the default values with a single command.
Beginning in privileged EXEC mode, follow these steps to reset the 802.1x configuration to the default
values:
Displaying 802.1x Statistics and Status
To display 802.1x statistics for all interfaces, use the
show dot1x statistics
privileged EXEC command.
To display 802.1x statistics for a specific interface, use the
show dot1x statistics
interface
interface-id
privileged EXEC command.
To display the 802.1x administrative and operational status for the switch, use the
show dot1x
privileged
EXEC command. To display the 802.1x administrative and operational status for a specific interface, use
the
show dot1x interface
interface-id
privileged EXEC command.
Command
Purpose
Step 1
configure terminal
Enters global configuration mode.
Step 2
interface
interface-id
Enters interface configuration mode, and specify the interface to which
multiple hosts are indirectly attached.
Step 3
dot1x multiple-hosts
Allows multiple hosts (clients) on an 802.1x-authorized port.
Make sure that the
dot1x port-control
interface configuration command
is set to
auto
for the specified interface.
Step 4
end
Returns to privileged EXEC mode.
Step 5
show dot1x interface
interface-id
Verifies your entries.
Step 6
copy running-config startup-config
(Optional) Saves your entries in the configuration file.
Command
Purpose
Step 1
configure terminal
Enters global configuration mode.
Step 2
dot1x default
Resets the configurable 802.1x parameters to the default values.
Step 3
end
Returns to privileged EXEC mode.
Step 4
show dot1x
Verifies your entries.
Step 5
copy running-config startup-config
(Optional) Saves your entries in the configuration file.