From: Farrukh Haroon (farrukhharoon@gmail.com)
Date: Thu Jun 26 2008 - 09:59:30 ART
There are two parts of Dot1x. Authentication and Authorization.
Authentication:
If you want users to use the access VLAN already assigned on the switch
after entering the appropriate username/password.
Authorization: (OPTIONAL)
Use a Radius server (like ACS) to put the user in a specific VLAN after he
authenticates.
If you are using the 'authorization' part, you don't assign a VLAN to the
access port. That is pushed automatically from the Radius Server.
Regards
Farrukh
On Thu, Jun 26, 2008 at 3:09 PM, David Lonnie <david.lonnie@gmail.com>
wrote:
> Hi, experts:
>
> A question about Dot1x:
>
> Configuration on SW 3560:
>
> interface FastEthernet0/1
> switchport access vlan 500
> switchport mode access
> dot1x pae authenticator
> dot1x port-control auto
> dot1x guest-vlan 500
> dot1x auth-fail vlan 500
>
> i configured dot1x authentication on interface fa0/1 of SW1,and then i
> divide this port into vlan 500.
> does dot1x authentication still works?
>
>
>
>
> David.
>
>
> _______________________________________________________________________
> Subscription information may be found at:
> http://www.groupstudy.com/list/CCIELab.html
This archive was generated by hypermail 2.1.4 : Tue Jul 01 2008 - 06:23:23 ART