Cisco WS-C4003 Software Guide - Page 395

Setting and Enabling Automatic Reauthentication of the Supplicant, set dot1x re-authperiod

Page 395 highlights

Chapter 27 Configuring Switch Access Using AAA Configuring Authentication This example shows how to enable 802.1x authentication on port 1 in module 4, initialize 802.1x authentication on the same port, and verify the configuration: Console> (enable) set port dot1x 4/1 port-control auto Port 4/1 dot1x port-control is set to auto. Trunking disabled for port 4/1 due to Dot1x feature. Spantree port fast start option enabled for port 4/1. Console> (enable) set port dot1x 4/1 initialize Port 4/1 initializing... Port 4/1 dot1x initialization complete. Console> show port dot1x 4/1 Port Auth-State BEnd-State Port-Control Port-Status 4/1 connecting finished auto unauthorized Port Multiple-Host Re-authentication 4/1 disabled disabled Setting and Enabling Automatic Reauthentication of the Supplicant You can specify how often 802.1x authentication reauthenticates the supplicant if you do so prior to enabling automatic 802.1x supplicant reauthentication. If you do not specify a time period prior to enabling supplicant reauthentication, 802.1x defaults to 3600 seconds (valid values are from 1 to 65535 seconds). Automatic 802.1x supplicant reauthentication can be enabled for supplicants connected to a specific port. To manually reauthenticate the supplicant connected to a specific port, see the "Manually Reauthenticating the Supplicant" section on page 27-42. To set how often 802.1x authentication reauthenticates the supplicant and enable automatic 802.1x reauthentication, perform this task in privileged mode: Step 1 Step 2 Step 3 Task Set the time constant for reauthenticating the supplicant. Enable reauthentication. Verify the 802.1x configuration. Command set dot1x re-authperiod seconds set port dot1x mod/port re-authentication enable show port dot1x mod/port This example shows how to set automatic reauthentication to 7200 seconds, enable 802.1x reauthentication, and verify the configuration: Console> (enable) set dot1x re-authperiod 7200 dot1x re-authperiod set to 7200 seconds Console> (enable) set port dot1x 4/1 re-authentication enable Port 4/1 re-authentication enabled. Console> (enable) show port dot1x 4/1 Port Auth-State BEnd-State Port-Control Port-Status 4/1 connecting finished auto unauthorized Port Multiple Host Re-authentication 4/1 disabled enabled 78-12647-02 Software Configuration Guide-Catalyst 4000 Family, Catalyst 2948G, Catalyst 2980G, Releases 6.3 and 6.4 27-41

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496
  • 497
  • 498
  • 499
  • 500
  • 501
  • 502
  • 503
  • 504
  • 505
  • 506
  • 507
  • 508
  • 509
  • 510

27-41
Software Configuration Guide—Catalyst 4000 Family, Catalyst 2948G, Catalyst 2980G, Releases 6.3 and 6.4
78-12647-02
Chapter 27
Configuring Switch Access Using AAA
Configuring Authentication
This example shows how to enable 802.1x authentication on port 1 in module 4, initialize 802.1x
authentication on the same port, and verify the configuration:
Console> (enable)
set port dot1x 4/1 port-control auto
Port 4/1 dot1x port-control is set to auto.
Trunking disabled for port 4/1 due to Dot1x feature.
Spantree port fast start option enabled for port 4/1.
Console> (enable)
set port dot1x 4/1 initialize
Port 4/1 initializing...
Port 4/1 dot1x initialization complete.
Console>
show port dot1x 4/1
Port
Auth-State
BEnd-State Port-Control
Port-Status
----- ------------------- ---------- ------------------- -------------
4/1
connecting
finished
auto
unauthorized
Port
Multiple-Host Re-authentication
----- ------------- -----------------
4/1
disabled
disabled
Setting and Enabling Automatic Reauthentication of the Supplicant
You can specify how often 802.1x authentication reauthenticates the supplicant if you do so prior to
enabling automatic 802.1x supplicant reauthentication. If you do not specify a time period prior to
enabling supplicant reauthentication, 802.1x defaults to 3600 seconds (valid values are from 1 to
65535 seconds).
Automatic 802.1x supplicant reauthentication can be enabled for supplicants connected to a specific
port. To manually reauthenticate the supplicant connected to a specific port, see the
“Manually
Reauthenticating the Supplicant” section on page 27-42
.
To set how often 802.1x authentication reauthenticates the supplicant and enable automatic 802.1x
reauthentication, perform this task in privileged mode:
This example shows how to set automatic reauthentication to 7200 seconds, enable 802.1x
reauthentication, and verify the configuration:
Console> (enable)
set dot1x re-authperiod 7200
dot1x re-authperiod set to 7200 seconds
Console> (enable)
set port dot1x 4/1 re-authentication enable
Port 4/1 re-authentication enabled.
Console> (enable)
show port dot1x 4/1
Port
Auth-State
BEnd-State Port-Control
Port-Status
----- ------------------- ---------- ------------------- -------------
4/1
connecting
finished
auto
unauthorized
Port
Multiple Host Re-authentication
----- ------------- -----------------
4/1
disabled
enabled
Task
Command
Step 1
Set the time constant for reauthenticating the
supplicant.
set dot1x re-authperiod
seconds
Step 2
Enable reauthentication.
set port dot1x
mod
/
port
re-authentication enable
Step 3
Verify the 802.1x configuration.
show port dot1x
mod
/
port