Aaa Authentication Dot1X - Cisco NM-8B-U - HW ROUTERS L-M User Manual

16- and 36-port ethernet switch module for cisco 2600 series, cisco 3600 series, and cisco 3700 series
Table of Contents

Advertisement

16- and 36-Port Ethernet Switch Module for Cisco 2600 Series, Cisco 3600 Series, and Cisco 3700 Series

aaa authentication dot1x

To specify one or more authentication, authorization, and accounting (AAA) methods for use on
interfaces running IEEE 802.1x, use the aaa authentication dot1x command in global configuration
mode. To disable authentication, use the no form of this command.
Syntax Description
default
listname
method1
[method2...]
Defaults
No authentication is performed.
Command Modes
Global configuration
Command History
Release
12.1(6)EA2
12.2(15)ZJ
Usage Guidelines
The method argument identifies the list of methods that the authentication algorithm tries in the given
sequence to validate the password provided by the client. The only method that is truly 802.1x-compliant
is the group radius method, in which the client data is validated against a RADIUS authentication
server. The remaining methods enable AAA to authenticate the client by using locally configured data.
For example, the local and local-case methods use the username and password that are saved in the Cisco
IOS configuration file. The enable and line methods use the enable and line passwords for
authentication.
aaa authentication dot1x {default | listname} method1 [method2...]
no aaa authentication dot1x {default | listname} method1 [method2...]
Uses the listed authentication methods that follow this argument as the default
list of methods when a user logs in.
Character string used to name the list of authentication methods tried when a
user logs in.
At least one of these keywords:
enable—Uses the enable password for authentication.
group radius—Uses the list of all Remote Authentication Dial-In User
Service (RADIUS) servers for authentication.
line—Uses the line password for authentication.
local—Uses the local username database for authentication.
local-case—Uses the case-sensitive local username database for
authentication.
none—Uses no authentication. The client is automatically authenticated by
the switch without using the information supplied by the client.
Modification
This command was introduced.
This command was implemented on the following platforms: Cisco 2600
series, Cisco 3600 series, and Cisco 3700 series routers.
Cisco IOS Release 12.2(2)XT, 12.2(8)T, and 12.2(15)ZJ
aaa authentication dot1x
159

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents