02.10.2013 Views

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Figure 482 shows configuration in<strong>for</strong>mation <strong>for</strong> a port <strong>for</strong> which <strong>the</strong> au<strong>the</strong>nticator terminates <strong>the</strong><br />

au<strong>the</strong>ntication process <strong>for</strong> an unresponsive supplicant or server after 15 seconds.<br />

Figure 482 Configuring a Timeout<br />

Dynamic VLAN Assignment with Port Au<strong>the</strong>ntication<br />

<strong>FTOS</strong> supports dynamic VLAN assignment when using 802.1X, as described in <strong>the</strong> following steps:<br />

Step Task<br />

<strong>Force10</strong>(conf-if-gi-2/1)#dot1x port-control <strong>for</strong>ce-authorized<br />

<strong>Force10</strong>(conf-if-gi-2/1)#do show dot1x interface gigabite<strong>the</strong>rnet 2/1<br />

802.1x in<strong>for</strong>mation on Gi 2/1:<br />

-----------------------------<br />

Dot1x Status: Enable<br />

Port Control: FORCE_AUTHORIZED<br />

Port Auth Status: UNAUTHORIZED<br />

Re-Au<strong>the</strong>ntication: Disable<br />

Untagged VLAN id: None<br />

Guest VLAN: Disable<br />

Guest VLAN id: NONE<br />

Auth-Fail VLAN: Disable<br />

Auth-Fail VLAN id: NONE<br />

Auth-Fail Max-Attempts: NONE<br />

Tx Period: 90 seconds<br />

Quiet Period: 120 seconds<br />

ReAuth Max: 10<br />

Supplicant Timeout: 15 seconds<br />

Server Timeout: 15 seconds<br />

Re-Auth Interval: 7200 seconds<br />

Max-EAP-Req: 10<br />

Auth Type: SINGLE_HOST<br />

Auth PAE State: Initialize<br />

Backend State: Initialize<br />

1 Configure 8021.x globally and at interface level ( see Enabling 802.1X on page 677) along with relevant<br />

RADIUS server configurations (Figure 483)<br />

2 Make <strong>the</strong> inteface a switchport so that it can be assigned to a VLAN.<br />

3 Create <strong>the</strong> VLAN to which <strong>the</strong> interface will be assigned.<br />

4 Connect <strong>the</strong> supplicant to <strong>the</strong> port configured <strong>for</strong> 802.1X.<br />

New Supplicant and Server Timeouts<br />

5 Verify that <strong>the</strong> port has been authorized and placed in <strong>the</strong> desired VLAN (Figure 483, red text).<br />

684 802.1X

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!