
ii
Authorization VLAN··································································································································72
Guest VLAN·············································································································································74
Auth-Fail VLAN ········································································································································75
Critical VLAN············································································································································76
Using 802.1X authentication with other features ·····························································································78
ACL assignment·······································································································································78
User profile assignment ···························································································································79
EAD assistant···········································································································································79
Configuration prerequisites······························································································································79
802.1X configuration task list···························································································································80
Enabling 802.1X···············································································································································80
Enabling EAP relay or EAP termination···········································································································81
Setting the port authorization state ··················································································································81
Specifying an access control method ··············································································································82
Setting the maximum number of concurrent 802.1X users on a port·······························································82
Setting the maximum number of authentication request attempts···································································82
Setting the 802.1X authentication timeout timers ····························································································83
Configuring the online user handshake feature ·······························································································83
Configuration guidelines···························································································································83
Configuration procedure···························································································································84
Configuring the authentication trigger feature··································································································84
Configuration guidelines···························································································································84
Configuration procedure···························································································································84
Specifying a mandatory authentication domain on a port················································································85
Setting the quiet timer······································································································································85
Enabling the periodic online user reauthentication feature··············································································86
Configuring an 802.1X guest VLAN·················································································································86
Configuration guidelines···························································································································86
Configuration prerequisites······················································································································87
Configuration procedure···························································································································87
Enabling 802.1X guest VLAN assignment delay ·····························································································87
Configuring an 802.1X Auth-Fail VLAN ···········································································································88
Configuration guidelines···························································································································88
Configuration prerequisites······················································································································89
Configuration procedure···························································································································89
Configuring an 802.1X critical VLAN················································································································89
Configuration guidelines···························································································································89
Configuration prerequisites······················································································································89
Configuration procedure···························································································································90
Enabling 802.1X critical voice VLAN················································································································90
Configuration prerequisites······················································································································90
Configuration procedure···························································································································91
Sending 802.1X protocol packets out of a port without VLAN tags ·································································91
Specifying supported domain name delimiters ································································································91
Configuring the EAD assistant feature·············································································································92
Displaying and maintaining 802.1X··················································································································93
802.1X authentication configuration examples ································································································93
Basic 802.1X authentication configuration example ················································································93
802.1X guest VLAN and authorization VLAN configuration example ······················································95
802.1X with ACL assignment configuration example···············································································98
802.1X with EAD assistant configuration example···················································································99
Troubleshooting 802.1X·································································································································102
EAD assistant for Web browser users ···································································································102
Configuring MAC authentication ·································································103
Overview························································································································································103
User account policies·····························································································································103
Authentication methods··························································································································103
VLAN assignment ··································································································································103
ACL assignment·····································································································································105
User profile assignment ·························································································································106
Periodic MAC reauthentication···············································································································106