Users Guide

Table Of Contents
338 Authentication, Authorization, and Accounting
authentication port-
control {force-
authorized | force-
unauthorized | auto}
Specify the authentication mode for the port.
NOTE: For standard 802.1X implementations in which one
client is connected to one port, use the authentication port-
control auto command to enable 802.1X authentication on the
port.
auto — Enables 802.1X authentication on the interface
and causes the port to transition to the authorized or
unauthorized state based on the 802.1X authentication
exchange between the switch and the client. Once the
port is authenticated by any host, additional hosts on the
port will have access to network resources using the port
PVID.
force-authorized — Disables 802.1X authentication on
the interface and causes the port to transition to the
authorized state without any authentication exchange
required. The port sends and receives normal traffic
without 802.1X-based authentication of the client.
force-unauthorized — Denies all access through this
interface by forcing the port to transition to the
unauthorized state, ignoring all attempts by the client to
authenticate. The switch cannot provide authentication
services to the client through the interface.
mab [auth-type
{pap|eap-md5|chap}]
This command can be used to enable MAB on the
interface and select the authentication type.
CTRL + Z Exit to Privileged Exec mode.
show dot1x View the current 802.1X status.
show authentication
clients {all | interface}
View information about 802.1X clients that have
successfully authenticated and are connected to the
switch. The interface variable includes the interface type
and number.
show dot1x users
[username username]
View the 802.1X authenticated users for the switch.
Command Purpose