Cisco 802.1x Concepts and Configuration

Date: Oct 31, 2011

Return to the article

This article takes a look at the different roles that are defined within the 802.1X standard, a general review of how the process works, and a review of how the basic configuration is performed on a Cisco device.

The IEEE 802.1x standard was developed to provide a method to authenticate devices attempting to access a switchport. Access to a switchport in most organizations provides access to the internal network and with this, a direct connection to multiple resources that require a high level of security. The IEEE 802.1x standard is one of the technologies that can be used to provide security in these situations. The standard provides a method to allow traffic to be sent and received over a switchport after an authentication sequence has been performed. Authentication credentials are handled by a central authentication server; once this process has succeeded the switchport will allow traffic as normal. This article takes a look at the different roles that are defined within the standard, a general review of how the process works and a review of how the basic configuration is performed on a Cisco device.

Concepts

There are some basic roles that are defined within the IEEE 802.1x standard:

Each switchport configured to be an IEEE 802.1x supplicant can be in one of two states: unauthorized or authorized. An unauthorized switchport will only allow three types of traffic: Extensible Authentication Protocol over LAN (EAPOL) (used for authentication), Cisco Discovery Protocol (CDP) and Spanning Tree Protocol (STP); once the switchport has successfully authenticated, normal traffic is allowed freely.

Authentication traffic between the supplicant and the authentication server is handled through the Extensible Authentication Protocol (EAP). In LAN environments, the EAP packet is encapsulated in an EAPOL packet transported over the LAN to the authenticator and then re-encapsulated inside a Remote Authentication Dial In User Service (RADIUS) packet. There are a number of different EAP methods that can be used to authenticate, some of these include:

Configuration

There are a number of things that must be reviewed before configuring IEEE 802.1x on a Cisco device. On Cisco devices there are three different IEEE 802.1x switchport states to select from; these include:

As will be shown, the final step in a typical IEEE 802.1x configuration is changing the switchport state to Auto.

Another option that is available is altering the switchport host mode. By default, a switchport will only allow a single host to be authenticated at a time. However, this behavior can be altered by changing the switchport host mode. There are a number of different host modes that are supported; these include:

As shown, there are a number of different ways that IEEE 802.1x can be configured, this article only shows the commands for a basic configuration. More advanced configuration options can be found at Cisco.com.

Table 1 below shows the commands that can be used for basic IEEE 802.1x configuration.

Table 1

Step 1

Enter privileged mode

router>enable

Step 2

Enter global configuration mode

router#configure terminal

Step 3

Globally enable IEEE 802.1x

router(config)#dot1x system-auth-control

Step 4

Enable AAA

router(config)#aaa new-model

Step 5

Enable IEEE 802.1x AAA authentication

router(config)#aaa authentication dot1x default group radius

Step 6

Enter interface configuration mode

router(config)#interface interface

Step 7

Configure the switchport mode to access

router(config-if)#switchport mode access

Step 8

Configure the switchport to act as the IEEE 802.1x authenticator

router(config-if)#dot1x pae authenticator

Step 9

(Optional) Configure the switchport IEEE 802.1x host mode

router(config-if)#authentication host-mode [single-host | multi-auth | multi-domain | multi-host]

Step 10

Configure the switchport IEEE 802.1x state

router(config-if)#authentication port-control [auto | force-authorized | force-unauthorized]

Summary

There are a number of different configuration possibilities that can be used when implementing IEEE 802.1x that enable it to fit into almost any environment and to solve a number of physical switchport security issues. This article only takes a look at the highlights of what is available; those responsible for these areas of an organization's network should take a close look at what is possible with the equipment being used and take advantage of these features. Hopefully, this article has given enough of an introduction to what is possible with IEEE 802.1x and will help in its future use.

800 East 96th Street, Indianapolis, Indiana 46240

sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |