Flexible Authentication
MaxReq
TxPeriod
Flexible Authentication
Flexible Authentication sequencing allows a user to enable all or some authentication methods on a
router port and specify the order in which the methods should be executed.
Configuring Flexible Authentication
For more information about configuring of Flexible Authentication, see:
http://www.cisco.com/c/en/us/products/collateral/ios-nx-os-software/identity-based-networking-servic
e/application_note_c27-573287.html
Host mode
Only single-host mode is supported for the Identity features on the Onboard Gigabit Ethernet Layer 3
ports. In single-host mode, only one client can be connected to the IEEE 802.1X-enabled router port.
The router detects the client by sending an EAPol frame when the port link state changes to up state. If
a client leaves or is replaced with another client, the router changes the port link state to down, and the
port returns to the unauthorized state.
Open Access
The Open Access feature allows clients or devices to gain network access before authentication is
performed. This is primarily required for the Preboot eXecution Environment (PXE) scenario where a
device is required to access the network before PXE times out and downloads a bootable image, which
contains a supplicant.
Configuring Open Access
Perform these steps to configure Open Access.
SUMMARY STEPS
1.
2.
3.
4.
5.
Cisco 3900 Series, Cisco 2900 Series, and Cisco 1900 Series Integrated Services Routers Generation 2 Software Configuration Guide
162
= 2
= 30
enable
configure terminal
interface gigabitethernet slot / port
authentication open
end
Chapter
Configuring Identity Features on Layer 3 Interface