8-5
Catalyst 2950 Desktop Switch Software Configuration Guide
78-14982-01
Chapter 8 Configuring 802.1X Port-Based Authentication
Configuring 802.1X Authentication
Supported Topologies
The 802.1X port-based authentication is supported in two topologies:
• Point-to-point
• Wireless LAN
In a point-to-point configuration (see Figure 8-1 on page 8-2), only one client can be connected to the
802.1X-enabled switch port. The switch detects the client when the port link state changes to the up state.
If a client leaves or is replaced with another client, the switch changes the port link state to down, and
the port returns to the unauthorized state.
Figure 8-3 shows 802.1X port-based authentication in a wireless LAN. The 802.1X port is configured
as a multiple-host port that becomes authorized as soon as one client is authenticated. When the port is
authorized, all other hosts indirectly attached to the port are granted access to the network. If the port
becomes unauthorized (re-authentication fails or an EAPOL-logoff message is received), the switch
denies access to the network to all of the attached clients. In this topology, the wireless access point is
responsible for authenticating the clients attached to it, and the wireless access point acts as a client to
the switch.
Figure 8-3 Wireless LAN Example
Configuring 802.1X Authentication
These sections describe how to configure 802.1X port-based authentication on your switch:
• Default 802.1X Configuration, page 8-6
• 802.1X Configuration Guidelines, page 8-7
• Enabling 802.1X Authentication, page 8-8 (required)
• Configuring the Switch-to-RADIUS-Server Communication, page 8-9 (required)
• Enabling Periodic Re-Authentication, page 8-10 (optional)
• Manually Re-Authenticating a Client Connected to a Port, page 8-11 (optional)
• Changing the Quiet Period, page 8-11 (optional)
• Changing the Switch-to-Client Retransmission Time, page 8-12 (optional)
• Setting the Switch-to-Client Frame-Retransmission Number, page 8-13 (optional)
• Enabling Multiple Hosts, page 8-13 (optional)
• Resetting the 802.1X Configuration to the Default Values, page 8-14 (optional)
Wireless clients
Access point
Catalyst 2950 or
3550 switch
Authentication
server
(RADIUS)
74617