Users Guide

344 Authentication, Authorization, and Accounting
What is the Internal Authentication Server?
The Internal Authentication Server (IAS) is a dedicated local database for
authentication of users for network access through 802.1X. In this database,
the switch maintains a list of username and password combinations to use for
802.1X authentication. Entries can be created in the database manually, or
the IAS information can be uploaded to the switch.
If the authentication method for 802.1X is IAS, the switch uses the locally
stored list of username and passwords to provide port-based authentication to
users instead of using an external authentication server. Authentication using
the IAS supports the EAP-MD5 method only.
Default 802.1X Values
Table 10-12 lists the default values for the 802.1X features.
NOTE: The IAS database does not support VLAN assignments or DiffServ
policy/ACL assignments.
Table 10-12. Default Port-Based Security Values
Feature Description
Global 802.1X status Disabled
802.1X authentication method None
Per-port 802.1X status Disabled
Port authentication mode Auto mode
Port authentication state Unauthorized
Periodic reauthentication Disabled
Seconds between reauthentication
attempts
3600
Authentication server timeout 30 seconds
Resending EAP identity Request 30 seconds
Quiet period 60 seconds
Supplicant timeout 30 seconds
Max EAP request 2 times