02.10.2013 Views

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

In Figure 483 shows <strong>the</strong> configuration on <strong>the</strong> <strong>Force10</strong> system be<strong>for</strong>e connecting <strong>the</strong> end-user device in<br />

black and blue text, and after connecting <strong>the</strong> device in red text. The blue text corresponds to <strong>the</strong> preceding<br />

numbered steps on dynamic VLAN assignment with 802.1X.<br />

Figure 483 Dynamic VLAN Assignment with 802.1X<br />

<strong>Force10</strong>#show dot1x interface gigabite<strong>the</strong>rnet 1/10<br />

802.1x in<strong>for</strong>mation on Gi 1/10:<br />

-----------------------------<br />

Dot1x Status: Enable<br />

Port Control: AUTO<br />

Port Auth Status: AUTHORIZED<br />

Re-Au<strong>the</strong>ntication: Disable<br />

Untagged VLAN id: 400<br />

Tx Period: 30 seconds<br />

Quiet Period: 60 seconds<br />

ReAuth Max: 2<br />

Supplicant Timeout: 30 seconds<br />

Server Timeout: 30 seconds<br />

Re-Auth Interval: 3600 seconds<br />

Max-EAP-Req: 2<br />

Auth Type: SINGLE_HOST<br />

Auth PAE State: Au<strong>the</strong>nticated<br />

Backend State: Idle<br />

Guest and Au<strong>the</strong>ntication-fail VLANs<br />

1/10<br />

<strong>Force10</strong>(conf-if-gi-1/10)#show config<br />

interface GigabitE<strong>the</strong>rnet 1/10<br />

no ip address<br />

switchport<br />

dot1x au<strong>the</strong>ntication<br />

no shutdow<br />

End-user Device <strong>Force10</strong> switch<br />

4<br />

<strong>Force10</strong>(conf-if-vl-400)# show config<br />

interface Vlan 400 3<br />

no ip address<br />

shutdown<br />

<strong>Force10</strong>#show vlan<br />

Codes: * - Default VLAN, G - GVRP VLANs<br />

Q: U - Untagged, T - Tagged<br />

x - Dot1x untagged, X - Dot1x tagged<br />

G - GVRP tagged<br />

NUM Status Description Q Ports<br />

* 1 Inactive U Gi 1/10<br />

400 Inactive<br />

<strong>Force10</strong>#show vlan<br />

Codes: * - Default VLAN, G - GVRP VLANs<br />

Q: U - Untagged, T - Tagged<br />

x - Dot1x untagged, X - Dot1x tagged<br />

G - GVRP tagged<br />

NUM Status Description Q Ports<br />

* 1 Inactive<br />

400 Active U Gi 1/10<br />

Typically, <strong>the</strong> au<strong>the</strong>nticator (<strong>Force10</strong> system) denys <strong>the</strong> supplicant access to <strong>the</strong> network until <strong>the</strong><br />

supplicant is au<strong>the</strong>nticated. If <strong>the</strong> supplicant is au<strong>the</strong>nticated, <strong>the</strong> au<strong>the</strong>nticator enables <strong>the</strong> port and places<br />

it in ei<strong>the</strong>r <strong>the</strong> VLAN <strong>for</strong> which <strong>the</strong> port is configured, or <strong>the</strong> VLAN that <strong>the</strong> au<strong>the</strong>ntication server indicates<br />

in <strong>the</strong> au<strong>the</strong>ntication data.<br />

Note: Ports cannot be dynamically assigned to <strong>the</strong> default VLAN.<br />

radius-server host 10.11.197.169 auth-port 1645<br />

key 7 387a7f2df5969da4<br />

RADIUS Server<br />

fnC0065mp<br />

<strong>FTOS</strong> <strong>Configuration</strong> <strong>Guide</strong>, version 7.7.1.0 685<br />

2<br />

1<br />

1

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!