Explains IEEE 802.1X network access control and provides guidance for configuring port and node authentication through the APIC GUI, NX-OS-style CLI, and REST API.
This chapter contains the following sections:
802.1X authentication
Describes how 802.1X uses an authentication server and EAPOL traffic to control client access through Cisco NX-OS device ports.
802.1X host modes
Describes 802.1X host modes, which determine how many endpoints can use a port and how the system authenticates each endpoint.
802.1X authentication modes
Describes the EAP and MAB authentication modes that Cisco ACI uses to authenticate endpoints and control network access.
802.1X Guidelines and limitations
Lists the supported interfaces, platforms, authentication behaviors, downgrade considerations, and MTU requirements for deploying 802.1X port-based authentication in a Cisco ACI fabric.
802.1X and RADIUS configuration
Describes how Cisco APIC activates 802.1X and RADIUS processes and uses their configurations to authenticate endpoints on network interfaces.
Configure 802.1X node authentication using the NX-OS-style CLI
Configures 802.1X node authentication by creating a RADIUS group, port authentication policy, policy group, and leaf switch profile using the NX-OS-style CLI.
Configure 802.1X port authentication using the REST API
Creates, updates, and deletes an 802.1X port authentication policy by submitting XML payloads to the Cisco APIC REST API.
Configure 802.1X node authentication using the REST API
Creates, updates, and deletes an 802.1X node authentication policy by submitting XML payloads to the Cisco APIC REST API.