Cisco NME-X-23ES-1G User Guide - Page 217

dot1x port-control, force-unauthorized, show dot1x interface gigabitethernet0/2

Page 217 highlights

16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series show dot1x Authenticator State Machine State AUTHENTICATING Reauth Count 1 Backend State Machine State RESPONSE Request Count 0 Identifier (Server) 2 Reauthentication State Machine State INITIALIZE Note In the previous example, the supp-timeout, server-timeout, and reauth-max values in the Global 802.1x Parameters section are not configurable.When relaying a request from the Remote Authentication Dial-In User Service (RADIUS) authentication server to the client, the supp-timeout is the amount of time the switch waits for a response before it resends the request. When relaying a response from the client to the RADIUS authentication server, the server-timeout is the amount of time the switch waits for a reply before it resends the response. The reauth-max parameter is the maximum number of times that the switch tries to authenticate the client without receiving any response before the switch resets the port and restarts the authentication process. In the 802.1x Port Summary section of the example, the Status column shows whether the port is enabled for 802.1x (the dot1x port-control interface configuration command is set to auto or force-unauthorized). The Mode column shows the operational status of the port; for example, if you configure the dot1x port-control interface configuration command to force-unauthorized, but the port has not changed to that state, the Mode column displays auto. If you disable 802.1x, the Mode column displays n/a. The Authorized column shows the authorization state of the port. For information about port states, refer to the "Configuring 802.1x Port-Based Authentication" chapter in the Catalyst 2950 Desktop Switch Software Configuration Guide. The following is sample output from the show dot1x interface gigabitethernet0/2 privileged EXEC command. Table 20 describes the fields in the output. Switch# show dot1x interface gigabitethernet0/2 802.1X is enabled on GigabitEthernet0/2 Status Authorized Port-control Auto Supplicant 0060.b0f8.fbfb Multiple Hosts Disallowed Current Identifier 3 Authenticator State Machine State AUTHENTICATED Reauth Count 0 Backend State Machine State IDLE Request Count 0 Identifier (Server) 2 Reauthentication State Machine State INITIALIZE Cisco IOS Release 12.2(2)XT, 12.2(8)T, and 12.2(15)ZJ 217

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246

16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series
show dot1x
217
Cisco IOS Release 12.2(2)XT, 12.2(8)T, and 12.2(15)ZJ
Authenticator State Machine
State
AUTHENTICATING
Reauth Count
1
Backend State Machine
State
RESPONSE
Request Count
0
Identifier (Server) 2
Reauthentication State Machine
State
INITIALIZE
Note
In the previous example, the supp-timeout, server-timeout, and reauth-max values in the Global
802.1x Parameters section are not configurable.When relaying a request from the Remote
Authentication Dial-In User Service (RADIUS) authentication server to the client, the supp-timeout
is the amount of time the switch waits for a response before it resends the request. When relaying a
response from the client to the RADIUS authentication server, the server-timeout is the amount of
time the switch waits for a reply before it resends the response. The reauth-max parameter is the
maximum number of times that the switch tries to authenticate the client without receiving any
response before the switch resets the port and restarts the authentication process.
In the 802.1x Port Summary section of the example, the Status column shows whether the port is enabled
for 802.1x (the
dot1x port-control
interface configuration command is set to
auto
or
force-unauthorized
). The Mode column shows the operational status of the port; for example, if you
configure the
dot1x port-control
interface configuration command to
force-unauthorized
, but the port
has not changed to that state, the Mode column displays
auto
. If you disable 802.1x, the Mode column
displays
n/a
.
The Authorized column shows the authorization state of the port. For information about port states, refer
to the “Configuring 802.1x Port-Based Authentication” chapter in the
Catalyst 2950 Desktop Switch
Software Configuration Guide
.
The following is sample output from the
show dot1x interface gigabitethernet0/2
privileged EXEC
command.
Table 20
describes the fields in the output.
Switch#
show dot1x interface gigabitethernet0/2
802.1X is enabled on GigabitEthernet0/2
Status
Authorized
Port-control
Auto
Supplicant
0060.b0f8.fbfb
Multiple Hosts
Disallowed
Current Identifier
3
Authenticator State Machine
State
AUTHENTICATED
Reauth Count
0
Backend State Machine
State
IDLE
Request Count
0
Identifier (Server) 2
Reauthentication State Machine
State
INITIALIZE