Describes how Cisco APIC activates 802.1X and RADIUS processes and uses their configurations to authenticate endpoints on network interfaces.
802.1X and RADIUS configuration is a port-based authentication setup that associates an 802.1X-enabled interface with a reachable RADIUS server group.
This setup has these characteristics:
-
Cisco APIC starts the 802.1X and RADIUS processes only when the corresponding configurations are present.
-
You must enable 802.1X authentication on each interface that authenticates connected endpoints.
-
RADIUS server configuration is separate from 802.1X configuration.
-
Successful authentication requires both 802.1X and RADIUS configuration.
Configuration relationships
The 802.1X and RADIUS components interact in these ways:
|
Component |
Behavior |
|---|---|
|
802.1X process |
Cisco APIC starts the |
|
RADIUS process |
Cisco APIC starts the |
|
Interface authentication |
802.1X authentication must be enabled on each interface that authenticates connected endpoints. Interfaces without 802.1X enabled retain their existing behavior. |
|
RADIUS server configuration |
Defines the RADIUS servers and the connectivity information that the system uses to reach them. |
|
RADIUS group association |
The 802.1X configuration references a configured RADIUS server group or the default RADIUS server group for authentication. |
You can configure 802.1X and RADIUS in either order. However, 802.1X authentication cannot succeed until both configurations are complete.