11.07.2015 Views

Catalyst 3750-E and 3560-E Switch Cisco IOS ... - DNIP . NET

Catalyst 3750-E and 3560-E Switch Cisco IOS ... - DNIP . NET

Catalyst 3750-E and 3560-E Switch Cisco IOS ... - DNIP . NET

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 2<strong>Catalyst</strong> <strong>3750</strong>-E <strong>and</strong> <strong>3560</strong>-E <strong>Switch</strong> <strong>Cisco</strong> <strong>IOS</strong> Comm<strong>and</strong>sdot1x critical (interface configuration)dot1x critical (interface configuration)Use the dot1x critical interface configuration comm<strong>and</strong> on the switch stack or on a st<strong>and</strong>alone switchto enable the inaccessible-authentication-bypass feature, also referred to as critical authentication or theauthentication, authorization, <strong>and</strong> accounting (AAA) fail policy. You can also configure the accessVLAN to which the switch assigns the critical port when the port is in the critical-authentication state.To disable the feature or return to default, use the no form of this comm<strong>and</strong>.dot1x critical [recovery action reinitialize | vlan vlan-id]no dot1x critical [recovery | vlan]Syntax Descriptionrecovery action reinitializevlan vlan-idEnable the inaccessible-authentication-bypass recovery feature, <strong>and</strong>specify that the recovery action is to authenticate the port when anauthentication server is available.Specify the access VLAN to which the switch can assign a criticalport. The range is from 1 to 4094.DefaultsThe inaccessible-authentication-bypass feature is disabled.The recovery action is not configured.The access VLAN is not configured.Comm<strong>and</strong> ModesInterface configurationComm<strong>and</strong> HistoryRelease12.2(35)SE2ModificationThis comm<strong>and</strong> was introduced.Usage GuidelinesTo specify the access VLAN to which the switch assigns a critical port when the port is in thecritical-authentication state, use the vlan vlan-id keywords. The specified type of VLAN must match thetype of port, as follows:• If the critical port is an access port, the VLAN must be an access VLAN.• If the critical port is a private VLAN host port, the VLAN must be a secondary private VLAN.• If the critical port is a routed port, you can specify a VLAN, but this is optional.If the client is running Windows XP <strong>and</strong> the critical port to which the client is connected is in thecritical-authentication state, Windows XP might report that the interface is not authenticated.If the Windows XP client is configured for DHCP <strong>and</strong> has an IP address from the DHCP server, receivingan EAP-Success message on a critical port might not re-initiate the DHCP configuration process.OL-9776-08<strong>Catalyst</strong> <strong>3750</strong>-E <strong>and</strong> <strong>3560</strong>-E <strong>Switch</strong> Comm<strong>and</strong> Reference2-157

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!