Cisco Catalyst 3560-X Software Configuration Manual page 313

Hide thumbs Also See for Catalyst 3560-X:
Table of Contents

Advertisement

Chapter 1
Configuring IEEE 802.1x Port-Based Authentication
RADIUS servers and new hosts cannot be authenticated, the switch connects those hosts to critical ports.
A new host trying to connect to the critical port is moved to a user-specified access VLAN, the critical
VLAN, and granted limited authentication.
With this release, you can enter the authentication event server dead action authorize voice interface
configuration command to configure the critical voice VLAN feature. When the ACS does not respond,
the port goes into critical authentication mode. When traffic coming from the host is tagged with the
voice VLAN, the connected device (the phone) is put in the configured voice VLAN for the port. The IP
phones learn the voice VLAN identification through CDP (Cisco devices) or through LLDP or DHCP.
You can configure the voice VLAN for a port by entering the switchport voice vlan vlan-id interface
configuration command.
This feature is supported in multidomain and multi-auth host modes. Although you can enter the
command when the switch in single-host or multi-host mode, the command has no effect unless the
device changes to multidomain or multi-auth host mode.
Beginning in privileged EXEC mode, follow these steps to configure critical voice VLAN on a port and
enable the inaccessible authentication bypass feature.
Command
Step 1
configure terminal
Step 2
radius-server dead-criteria
time time tries tries
Step 3
radius-server deadtime
minutes
OL-25303-03
Purpose
Enters global configuration mode.
Sets the conditions that are used to decide when a RADIUS server is considered un-
available or down (dead).
The range for time is from 1 to 120 seconds. The switch dynamically determines
a default seconds value between 10 and 60 seconds.
The range for tries is from 1 to 100. The switch dynamically determines a default
tries parameter between 10 and 100.
(Optional) Sets the number of minutes during which a RADIUS server is not sent
requests. The range is from 0 to 1440 minutes (24 hours). The default is 0 minutes.
Catalyst 3750-X and 3560-X Switch Software Configuration Guide
Understanding IEEE 802.1x Port-Based Authentication
1-25

Advertisement

Table of Contents
loading

This manual is also suitable for:

Catalyst 3750-x

Table of Contents