11.07.2015 Views

Catalyst 3750-E and 3560-E Switch Cisco IOS ... - DNIP . NET

Catalyst 3750-E and 3560-E Switch Cisco IOS ... - DNIP . NET

Catalyst 3750-E and 3560-E Switch Cisco IOS ... - DNIP . NET

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 2<strong>Catalyst</strong> <strong>3750</strong>-E <strong>and</strong> <strong>3560</strong>-E <strong>Switch</strong> <strong>Cisco</strong> <strong>IOS</strong> Comm<strong>and</strong>sdot1x port-controldot1x port-controlUse the dot1x port-control interface configuration comm<strong>and</strong> on the switch stack or on a st<strong>and</strong>aloneswitch to enable manual control of the authorization state of the port. Use the no form of this comm<strong>and</strong>to return to the default setting.dot1x port-control {auto | force-authorized | force-unauthorized}no dot1x port-controlSyntax Descriptionautoforce-authorizedforce-unauthorizedEnable authentication on the port <strong>and</strong> cause the port to change to the authorizedor unauthorized state based on the IEEE 802.1x authentication exchangebetween the switch <strong>and</strong> the client.Disable authentication on the port <strong>and</strong> cause the port to transition to theauthorized state without an authentication exchange. The port sends <strong>and</strong>receives normal traffic without authentication of the client.Deny all access through this port by forcing the port to change to theunauthorized state, ignoring all attempts by the client to authenticate. Theswitch cannot provide authentication services to the client through the port.DefaultsThe default is force-authorized.Comm<strong>and</strong> ModesInterface configurationComm<strong>and</strong> HistoryRelease12.2(35)SE2ModificationThis comm<strong>and</strong> was introduced.Usage GuidelinesYou must globally enable IEEE 802.1x authentication on the switch by using the dot1xsystem-auth-control global configuration comm<strong>and</strong> before enabling IEEE 802.1x authentication on aspecific port.The IEEE 802.1x st<strong>and</strong>ard is supported on Layer 2 static-access ports, voice VLAN ports, <strong>and</strong> Layer 3routed ports.You can use the auto keyword only if the port is not configured as one of these:• Trunk port—If you try to enable IEEE 802.1x authentication on a trunk port, an error messageappears, <strong>and</strong> IEEE 802.1x is not enabled. If you try to change the mode of an IEEE 802.1x-enabledport to trunk, an error message appears, <strong>and</strong> the port mode is not changed.• Dynamic ports—A port in dynamic mode can negotiate with its neighbor to become a trunk port. Ifyou try to enable IEEE 802.1x authentication on a dynamic port, an error message appears, <strong>and</strong>IEEE 802.1x authentication is not enabled. If you try to change the mode of an IEEE 802.1x-enabledport to dynamic, an error message appears, <strong>and</strong> the port mode is not changed.OL-9776-08<strong>Catalyst</strong> <strong>3750</strong>-E <strong>and</strong> <strong>3560</strong>-E <strong>Switch</strong> Comm<strong>and</strong> Reference2-171

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!