Configuration Guide Vol. 2


7.1.1 Command list

The following tables list IEEE802.1X configuration commands.

Table 7-1: List of configuration commands

Command name

Description

aaa accounting dot1x default

Enables the collection of accounting information by the RADIUS server.

aaa authentication dot1x default

Configures the switch to use the RADIUS server for IEEE 802.1X user authentication.

dot1x ignore-eapol-start

Configures the switch not to transmit EAP-Request/Identity packets in response to an EAPOL-Start message received from a supplicant.

dot1x logging enable

Sends IEEE802.1X operation log messages to syslog servers or email addresses (using E-Mail).

dot1x loglevel

Specifies the message level to write to the operation log.

dot1x max-req

Specifies the maximum number of times that the switch sends an EAP-Request/Identity packet when there is no response from the supplicant.

dot1x max-supplicant

Specifies the maximum number of authenticated users permitted per authentication unit.

dot1x multiple-hosts

dot1x multiple-authentication

Sets IEEE802.1X authentication submode.

dot1x port-control

Enables IEEE 802.1X authentication for the specified interfaces.

dot1x radius-server host

Specify IP of RADIUS servers for IEEE802.1X only.

dot1x reauthentication

Enables or disables periodic re-authentication of authenticated terminals.

dot1x supplicant-detection

Configures how terminal detection is performed when terminal authentication mode is specified as the authentication sub-mode.

dot1x system-auth-control

Enables IEEE 802.1X.

dot1x timeout keep-unauth

Sets the time to retain the communication shutdown status on an interface when an authentication request from multiple terminals is detected in single mode of the authentication submode.

dot1x timeout quiet-period

Configures how long the switch waits before allowing a supplicant that failed authentication (including re-authentication) to try again.

dot1x timeout reauth-period

Specifies the interval between re-authentication attempts for authenticated terminals.

dot1x timeout server-timeout

Specifies how long the switch waits for a response from the authentication server.

dot1x timeout supp-timeout

Configures how long the switch waits for a supplicant to respond to an EAP-Request/Identity packet.

dot1x timeout tx-period

Specifies the sending interval for EAP-Request/Identity packets.

The following lists the operation commands that check IEEE802.1X status.

Table 7-2: List of operation commands

Command name

Description

show dot1x

Shows the status of each authentication unit and information about authenticated supplicants.

show dot1x logging

Shows the operation log messages output by the IEEE 802.1X software.

show dot1x statistics

Shows statistics about IEEE 802.1X authentication.

clear dot1x auth-state

Clears information related to authenticated terminals.

clear dot1x logging

Clears the operation log messages output by the IEEE 802.1X software.

clear dot1x statistics

Resets IEEE 802.1X-related statistics to 0.

reauthenticate dot1x

Re-authenticates the status of IEEE 802.1X authentication.

restart dot1x

Restarts the IEEE 802.1X program.

dump protocols dot1x

Outputs the control table information and statistics gathered by the IEEE 802.1X software to a file.