Lists the supported interfaces, platforms, authentication behaviors, downgrade considerations, and MTU requirements for deploying 802.1X port-based authentication in a Cisco ACI fabric.
Review these guidelines and limitations before you configure 802.1X authentication in a Cisco ACI fabric.
Guidelines and limitations
Consider these guidelines and limitations before you configure 802.1X authentication:
-
Cisco ACI supports 802.1X authentication only on physical fabric access ports.
-
Cisco ACI does not support 802.1X authentication on port channels, virtual port channels, or subinterfaces.
-
Cisco ACI supports 802.1X authentication on individual member ports of a port channel, but not on the port channel interface.
-
Member ports with and without an 802.1X configuration can coexist in a port channel. To use 802.1X with the port channel, apply the same 802.1X configuration to all member ports.
-
When you enable 802.1X authentication, the system authenticates supplicants before enabling other Layer 2 or Layer 3 features on the Ethernet interface.
-
802.1X is supported only on EX- or FX-series leaf switches.
-
Release 3.2(1) does not support IPv6 for 802.1X clients.
-
When you downgrade to a release that does not support the configured host mode or authentication type, the 802.1X authentication type defaults to
none. After the downgrade, manually configure the host mode assingle-hostormulti-host, as required. -
Multi-authentication mode supports one voice client and multiple data clients. All data clients must belong to the same data VLAN and EPG.
-
You must configure Fail EPG/VLAN in the 802.1X node authentication policy.
-
In multidomain mode, connecting more than one voice client or more than one data client places the port in the security-disabled state.
-
The N9K-C9396PX, N9K-C93128TX, and N9K-M12PQ platforms do not support 802.1X.
-
When strong encryption is enabled, an IP packet that contains a certificate can exceed 1500 bytes. If the authenticator is reachable through the out-of-band interface, the system fragments the packets automatically. The Cisco ACI fabric does not support packet fragmentation for in-band traffic. To forward packets larger than 1500 bytes through the in-band management network, complete both actions:
-
Increase the control-plane MTU. Refer to the Cisco APIC System Management Configuration Guide for instructions.
The control-plane MTU is a global fabric-wide setting that applies to other protocols.
-
Verify that every device along the path supports and forwards jumbo-MTU packets.
-