Cisco SR224T Administration Guide - Page 246

Number of Violations, Edit., Interface, Host Authentication, Action on Violation, Traps

Page 246 highlights

Configuring Security Configuring 802.1X 17 - Unauthorized-Either the port control is Force Unauthorized and the port link is down, or the port control is Auto but a client has not been authenticated via the port. - Force-Authorized-Clients have full port access. - Single-host Lock-Port control is Auto and only a single client has been authenticated by using the port. - No Single Host-Port control is Auto and Multiple Hosts mode is enabled. At least one client has been authenticated. - Not in Auto Mode-Auto port control is not enabled. • Number of Violations-Displays the number of packets that arrive on the interface in single-host mode, from a host whose MAC address is not the supplicant MAC address. STEP 2 Select a port, and click Edit. The Edit Host and Session Authentication page is displayed. STEP 3 Enter the parameters. • Interface-Enter a port number for which host authentication is enabled. • Host Authentication-Select one of the modes. These modes are described above in Defining Host and Session Authentication. NOTE The following fields are only relevant if you select Single in the Host Authentication field. Single Host Violation Settings: • Action on Violation-Select the action to be applied to packets arriving in Single Session/Single Host mode, from a host whose MAC address is not the supplicant MAC address. The options are: - Protect (Discard)-Discards the packets. - Restrict (Forward)-Forwards the packets. - Shutdown-Discards the packets and shuts down the port. The ports remains shut down until reactivated, or until the switch is rebooted. • Traps (on single host violation)-Select to enable traps. NOTE Traps are SYSLOG-related and not SNMP-related. • Trap Frequency (on Single Host Violation)-Defines how often traps are sent to the host. This field can be defined only if multiple hosts are disabled. Cisco Small Business 200 Series Smart Switch Administration Guide 247

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283

Configuring Security
Configuring 802.1X
Cisco Small Business 200 Series Smart Switch Administration Guide
247
17
-
Unauthorized
—Either the port control is
Force Unauthorized
and the
port link is down, or the port control is
Auto
but a client has not been
authenticated via the port.
-
Force-Authorized
—Clients have full port access.
-
Single-host Lock
—Port control is
Auto
and only a single client has been
authenticated by using the port.
-
No Single Host
—Port control is
Auto
and Multiple Hosts mode is enabled.
At least one client has been authenticated.
-
Not in Auto Mode
—Auto port control is not enabled.
Number of Violations
—Displays the number of packets that arrive on the
interface in single-host mode, from a host whose MAC address is not the
supplicant MAC address.
STEP
2
Select a port, and click
Edit.
The
Edit Host and Session Authentication
page is
displayed.
STEP
3
Enter the parameters.
Interface
—Enter a port number for which host authentication is enabled.
Host Authentication
—Select one of the modes. These modes are
described above in
Defining Host and Session Authentication
.
NOTE
The following fields are only relevant if you select Single in the Host
Authentication field.
Single Host Violation Settings:
Action on Violation
—Select the action to be applied to packets arriving in
Single Session/Single Host mode, from a host whose MAC address is not
the supplicant MAC address. The options are:
-
Protect (Discard)
—Discards the packets.
-
Restrict (Forward)
—Forwards the packets.
-
Shutdown
—Discards the packets and shuts down the port. The ports
remains shut down until reactivated, or until the switch is rebooted.
Traps
(on single host violation)—Select to enable traps.
NOTE
Traps are SYSLOG-related and not SNMP-related.
Trap Frequency (on Single Host Violation)
—Defines how often traps are
sent to the host. This field can be defined only if multiple hosts are disabled.