CLI Reference Guide-R04

Table Of Contents
Chapter 8
| User Authentication Commands
802.1X Port Authentication
– 276 –
Default Setting
Discards all EAPOL frames when dot1x is globally disabled
Command Mode
Global Configuration
Command Usage
When this device is functioning as intermediate node in the network and does
not need to perform dot1x authentication, the dot1x eapol pass-through
command can be used to forward EAPOL frames from other switches on to the
authentication servers, thereby allowing the authentication process to still be
carried out by switches located on the edge of the network.
When this device is functioning as an edge switch but does not require any
attached clients to be authenticated, the no dot1x eapol-pass-through
command can be used to discard unnecessary EAPOL traffic.
Example
This example instructs the switch to pass all EAPOL frame through to any ports in
STP forwarding state.
Console(config)#dot1x eapol-pass-through
Console(config)#
dot1x system-auth-
control
This command enables IEEE 802.1X port authentication globally on the switch.
Use the no form to restore the default.
Syntax
[no] dot1x system-auth-control
Default Setting
Disabled
Command Mode
Global Configuration
Example
Console(config)#dot1x system-auth-control
Console(config)#