Access Security Guide K/KA/KB.15.15

Index
Symbols
802.1X access control
authenticate users, 338
authentication: local, 338
authentication: methods, 337
authentication: user-based, 338
authenticator:operation, 339
authenticator:unblock port, 338
client, effect of disconnect, 346
control all clients, 341
delay move to unauthorized-client VLAN;802.1X access
control:unauth-period command, 344
DHCP server, 347
display all 802.1X, MAC authentication
configuration;authentication:display all 802.1X, MAC
configurations, 73
EAP;802.1X access control:CHAP, 337
features, 337
force authorized;, 348
force unauthorized, 348
guest VLAN;guest VLAN, 343
GVRP:effect, 337, 352
GVRP;GVRP:effect on client authentication, 351
hierarchy of precedence in authentication session, 438
LACP not allowed;LACP:802.1X not allowed;, 356
meshing, not supported, 341
multiple clients, 346
multiple clients, same VLAN, 338
open port;802.1X access control:user-based:limit, 337
open VLAN: operating notes, 349
open VLAN: security breach, 349
open VLAN:mode, 345
open VLAN:VLAN, tagged, 344, 349
open VLAN:VLAN, tagged;802.1X access control:open
VLAN:VLAN, after authentication;, 346, 349
password for port access, 31
password for port-access, 46
port-based:access;802.1X access
control:port-based:open port, 337
port-based:client without authentication, 338
port-based:effect of Web/MAC auth operation;802.1X
access control:Web/MAC auth effect, 341
port-based:latest client, effect, 338
port-based:multiple client access, 338
port-based:multiple clients authenticating, 338
port-based:no client limit, 337
port-based:not recommended;ACL, IPv4:802.1X
port-based not recommended;ACL, IPv6:802.1X
port-based not recommended, 309
port-based:operation, 338
port-based:recommended use, 338
port-based:single client authenticates, 338
port-based:tagged VLAN membership, 338
port-based:unauthorized client risk, 338
port-based:untagged VLAN membership, 338
port-based:untagged VLAN membership;802.1X access
control:VLAN:untagged, 343
port-based:with Web/MAC authentication, 338
port-security use, 338
PVID, 349
RADIUS:effect on VLAN operation, 351
rules of operation, 340
security credentials saved to configuration file, 31, 48
supplicant statistics, note, 350
supplicant:client not using, 345
troubleshooting, gvrp, 351, 352
trunked port blocked;802.1X access control:blocked
port, trunked, 341
unauthorized-Client VLAN, multiple clients, 347
use model, open VLAN mode;802.1X access
control:open VLAN:use model, 343
used with port-security;802.1X access
control:port-security, with 802.1X, 350
user-based:access, 338
user-based:authentication, 339
user-based:client authentication, 338
user-based:client limit, 338, 350
user-based:client limit;, 337
user-based:clients use same VLAN, 343
user-based:tagged VLAN, 338
user-based:VLAN, 347
user-based:Web/MAC authenticated clients, 338
VLAN operation;VLAN:802.1X, 351
VLAN, assignment conflict, 184, 341
VLAN, membership priority;802.1X access
control:priority of VLAN, per-port, 339, 343
VLAN, priority, RADIUS, 345
VLAN, tagged membership, 345
VLAN:authorized-client, 346
VLAN:authorized-client;802.1X access
control:VLAN:RADIUS override, 345
VLAN:RADIUS assigned, effect, 347
VLAN:RADIUS-assigned;802.1X access
control:RADIUS:VLAN assignment, 345
VLAN:tagged, 344, 345
VLAN:unauthorized-client, best use, 347
VLAN:unauthorized-client, on different ports, 347
VLAN:untagged, 343, 344
A
aaa
port-access gvrp-vlans; aaa: gvrp-vlans, 336
aaa authentication
chap-radius, 145
peap-mschapv2, 145
privilege-mode
privilege-mode single sign-on, 131
TACACS
TACACS+ server, 124
ACL
CIDR:mask, 69
524 Index