02.10.2013 Views

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

• ForceUnauthorized an unauthorized state. A device connected to a port in this state is never subjected<br />

to <strong>the</strong> au<strong>the</strong>ntication process and is not allowed to communicate on <strong>the</strong> network. Placing <strong>the</strong> port in<br />

this state is <strong>the</strong> same as shutting down <strong>the</strong> port. Any attempt by <strong>the</strong> supplicant to initiate au<strong>the</strong>ntication<br />

is ignored.<br />

• Auto is an unauthorized state by default. A device connected to this port is this state is subjected to <strong>the</strong><br />

au<strong>the</strong>ntication process. If <strong>the</strong> process is successful, <strong>the</strong> port is authorized and <strong>the</strong> connected device can<br />

communicate on <strong>the</strong> network. All ports are placed in <strong>the</strong> auto state by default.<br />

To place a port in one of <strong>the</strong>se three states:<br />

Step Task Command Syntax Command Mode<br />

1 Place a port in <strong>the</strong><br />

ForceAuthorized,<br />

ForceUnauthorized, or Auto state.<br />

Figure 480 shows configuration in<strong>for</strong>mation <strong>for</strong> a port that has been <strong>for</strong>ce-authorized.<br />

Figure 480 Configuring Port-control<br />

dot1x port-control {<strong>for</strong>ce-authorized |<br />

<strong>for</strong>ce-unauthorized | auto}<br />

Default: auto<br />

<strong>Force10</strong>(conf-if-gi-2/1)#dot1x port-control <strong>for</strong>ce-authorized<br />

<strong>Force10</strong>(conf-if-gi-2/1)#do show dot1x interface gigabite<strong>the</strong>rnet 2/1<br />

802.1x in<strong>for</strong>mation on Gi 2/1:<br />

-----------------------------<br />

Dot1x Status: Enable<br />

Port Control: FORCE_AUTHORIZED<br />

Port Auth Status: UNAUTHORIZED<br />

Re-Au<strong>the</strong>ntication: Disable<br />

Untagged VLAN id: None<br />

Tx Period: 90 seconds<br />

Quiet Period: 120 seconds<br />

ReAuth Max: 2<br />

Supplicant Timeout: 30 seconds<br />

Server Timeout: 30 seconds<br />

Re-Auth Interval: 3600 seconds<br />

Max-EAP-Req: 10<br />

Auth Type: SINGLE_HOST<br />

Auth PAE State: Initialize<br />

Backend State: Initialize<br />

Auth PAE State: Initialize<br />

Backend State: Initialize<br />

New Port-control State<br />

INTERFACE<br />

<strong>FTOS</strong> <strong>Configuration</strong> <strong>Guide</strong>, version 7.7.1.0 681

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!