Cisco APIC Security Configuration Guide, Release 6.2(x)

PDF

Cisco APIC Security Configuration Guide, Release 6.2(x)

802.1X Guidelines and limitations

Want to summarize with AI?

Log in

Lists the supported interfaces, platforms, authentication behaviors, downgrade considerations, and MTU requirements for deploying 802.1X port-based authentication in a Cisco ACI fabric.


Review these guidelines and limitations before you configure 802.1X authentication in a Cisco ACI fabric.

Guidelines and limitations

Consider these guidelines and limitations before you configure 802.1X authentication:

  • Cisco ACI supports 802.1X authentication only on physical fabric access ports.

  • Cisco ACI does not support 802.1X authentication on port channels, virtual port channels, or subinterfaces.

  • Cisco ACI supports 802.1X authentication on individual member ports of a port channel, but not on the port channel interface.

  • Member ports with and without an 802.1X configuration can coexist in a port channel. To use 802.1X with the port channel, apply the same 802.1X configuration to all member ports.

  • When you enable 802.1X authentication, the system authenticates supplicants before enabling other Layer 2 or Layer 3 features on the Ethernet interface.

  • 802.1X is supported only on EX- or FX-series leaf switches.

  • Release 3.2(1) does not support IPv6 for 802.1X clients.

  • When you downgrade to a release that does not support the configured host mode or authentication type, the 802.1X authentication type defaults to none. After the downgrade, manually configure the host mode as single-host or multi-host, as required.

  • Multi-authentication mode supports one voice client and multiple data clients. All data clients must belong to the same data VLAN and EPG.

  • You must configure Fail EPG/VLAN in the 802.1X node authentication policy.

  • In multidomain mode, connecting more than one voice client or more than one data client places the port in the security-disabled state.

  • The N9K-C9396PX, N9K-C93128TX, and N9K-M12PQ platforms do not support 802.1X.

  • When strong encryption is enabled, an IP packet that contains a certificate can exceed 1500 bytes. If the authenticator is reachable through the out-of-band interface, the system fragments the packets automatically. The Cisco ACI fabric does not support packet fragmentation for in-band traffic. To forward packets larger than 1500 bytes through the in-band management network, complete both actions:

    • Increase the control-plane MTU. Refer to the Cisco APIC System Management Configuration Guide for instructions.

      Note

      The control-plane MTU is a global fabric-wide setting that applies to other protocols.

    • Verify that every device along the path supports and forwards jumbo-MTU packets.