Introduces 802.1X authentication, outlining its security functions, supported EAP methods, integration with Cisco devices, feature history, and requirements for AP credential provisioning and authentication processes on Wave 2 and Wi-Fi 6 APs.
IEEE 802.1X port-based authentication is a network security protocol that
-
prevents unauthorized devices from accessing the network
-
utilizes EAP authentication models to ensure secure communication, and
-
integrates with devices like routers, switches, and access points based on configuration.
Feature history
| Feature name |
Release information |
Feature description |
|---|---|---|
| 802.1X authentication |
Cisco IOS XE 16.9.1 |
IEEE 802.1X port-based authentication is a network security protocol that utilizes EAP authentication models to ensure secure communication, and integrates with devices like routers, switches, and access points based on configuration. |
| Access ports with dual port authentication |
Cisco IOS XE 17.17.1 |
The access ports with dual port authentication feature supports dual Ethernet ports on Cisco Catalyst 9136 APs and Cisco Wireless 9178I APs. |
Currently, Cisco Wave 2 and Wi-Fi 6 (802.11AX) APs support 802.1X authentication with switch ports for EAP-FAST, EAP-TLS, and EAP-PEAP methods. Configuration and credential provision to APs can be done through the controller.
If the AP is dot1x EAP-FAST, upon reboot, it should perform an anonymous PAC provision using ADH cipher suites to establish an authenticated tunnel. Authentication will fail if RADIUS servers do not support ADH cipher suites.