Administrator Guide

Security Commands 969
dot1x eapolflood
This command enables the flooding of received IEEE 802.1x frames in the
VLAN.
Syntax
dot1x eapolflood
Default Configuration
By default, the switch does not forward received IEEE 802.1x frames, even if
802.1x is not enabled on the switch. This is the default behavior required by
IEEE 802.1x-2010.
Command Mode
Global Configuration mode
User Guidelines
Local processing of IEEE 802.1x frames must be disabled (no dot1x system-
auth-control) for this capability to be enabled. This capability is useful in
situations where the authenticator device is placed one or more hops away
from the authenticating host. The intervening switch will flood all received
IEEE 802.1x frames in the VLAN.
Flooding of IEEE 802.1x frames makes end stations vulnerable to a denial of
service attack should another end station record and play back certain flooded
EAPOL frames at a high rate.
dot1x initialize
This command begins the initialization sequence on the specified port. This
command is only valid if the control mode for the specified port is auto or
mac-based. If the control mode is not auto or mac-based, an error will be
returned.
Syntax
dot1x initialize [interface interface-id]
interface-id
—The port to be initialized.
2CSNXXX_SWUM204.book Page 969 Monday, January 25, 2016 1:25 PM