Cisco SR224T-NA Administration Guide - Page 244

Administrative Port Control, Reauthentication Period

Page 244 highlights

Configuring Security Configuring 802.1X 17 • Administrative Port Control-Select the Administrative Port Authorization state. The options are: - Force Unauthorized-Denies the interface access by moving the interface into the unauthorized state. The switch does not provide authentication services to the client through the interface. - Auto-Enables port-based authentication and authorization on the switch. The interface moves between an authorized or unauthorized state based on the authentication exchange between the switch and the client. - Force Authorized-Authorizes the interface without authentication. • Authentication Method-Select the authentication method for the port. The options are: - 802.1X Only-802.1X authentication is the only authentication method performed on the port. • Periodic Reauthentication-Select to enable port re-authentication attempts after the specified Reauthentication Period. • Reauthentication Period-Enter the number of seconds after which the selected port is reauthenticated. • Reauthenticate Now-Select to enable immediate port re-authentication. • Authenticator State-Displays the defined port authorization state. The options are: - Force-Authorized-Controlled port state is set to Force-Authorized (forward traffic). NOTE If the port is not in Force-Unauthorized, it is in Auto Mode and the authenticator displays the state of the authentication in progress. After the port is authenticated, the state is shown as Authenticated. • Quiet Period-Enter the number of seconds that the switch remains in the quiet state following a failed authentication exchange. • Resending EAP-Enter the number of seconds that the switch waits for a response to an Extensible Authentication Protocol (EAP) request/identity frame from the supplicant (client) before resending the request. • Max EAP Requests-Enter the maximum number of EAP requests that can be sent. If a response is not received after the defined period (supplicant timeout), the authentication process is restarted. Cisco Small Business 200 Series Smart Switch Administration Guide 245

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283

Configuring Security
Configuring 802.1X
Cisco Small Business 200 Series Smart Switch Administration Guide
245
17
Administrative Port Control
—Select the Administrative Port Authorization
state. The options are:
-
Force Unauthorized
—Denies the interface access by moving the
interface into the unauthorized state. The switch does not provide
authentication services to the client through the interface.
-
Auto
—Enables port-based authentication and authorization on the
switch. The interface moves between an authorized or unauthorized
state based on the authentication exchange between the switch and the
client.
-
Force Authorized
—Authorizes the interface without authentication.
Authentication Method
—Select the authentication method for the port. The
options are:
-
802.1X Only
—802.1X authentication is the only authentication method
performed on the port.
Periodic Reauthentication
—Select to enable port re-authentication
attempts after the specified Reauthentication Period.
Reauthentication Period
—Enter the number of seconds after which the
selected port is reauthenticated.
Reauthenticate Now
—Select to enable immediate port re-authentication.
Authenticator State
—Displays the defined port authorization state. The
options are:
-
Force-Authorized
—Controlled port state is set to Force-Authorized
(forward traffic).
NOTE
If the port is not in Force-Unauthorized, it is in Auto Mode and the
authenticator displays the state of the authentication in progress. After
the port is authenticated, the state is shown as Authenticated.
Quiet Period
—Enter the number of seconds that the switch remains in the
quiet state following a failed authentication exchange.
Resending EAP
—Enter the number of seconds that the switch waits for a
response to an Extensible Authentication Protocol (EAP) request/identity
frame from the supplicant (client) before resending the request.
Max
EAP Requests
—Enter the maximum number of EAP requests that can
be sent. If a response is not received after the defined period (supplicant
timeout), the authentication process is restarted.