Describes how Cisco 8000 Series Routers control network access with 802.1X, MAC Authentication Bypass, fallback authentication, and RADIUS Change of Authorization.
Use this chapter to understand, configure, and verify port-based authentication for authorized and non-802.1X-capable client devices.
The chapter covers the following authentication capabilities:
-
802.1X port-based authentication with remote RADIUS or local EAP authentication
-
MAC Authentication Bypass (MAB) for devices that cannot use 802.1X
-
MAB fallback and authentication-method precedence
-
RADIUS Change of Authorization for active 802.1X and MAB sessions
Use the topics in this chapter to:
-
Control ingress traffic on physical ports until clients are authenticated
-
Configure client, authenticator, supplicant, RADIUS, and certificate settings
-
Review authentication status, counters, and system messages
-
Reauthenticate active sessions after an authorization policy changes
Port-based authentication methods
Explains how 802.1X and MAB control access to network services according to client capabilities, authentication parameters, and authentication results on Cisco 8000 Series Routers.
802.1X authentication with MAC Authentication Bypass fallback
Explains how MAB provides fallback authentication for clients that cannot complete 802.1X while preserving 802.1X as the preferred authentication method.
RADIUS Change of Authorization for 802.1X and MAB sessions
Explains how RADIUS CoA dynamically changes active 802.1X and MAB session attributes and initiates reauthentication without requiring complete session termination.