Specifications

Security Options 93
Chapter 5
FIGURE 5-23 Stateful 802.1x Configuration
Available configuration parameters are:
Authentication Enabled – Enables or disables stateful 802.1x authentication.
Default Role – If a client authenticates using stateful 802.1x, and the
authentication server does not provide role information, the default role will be
given to the client.
Request/Response Timeout – Specifies the maximum time to wait for a
response from the RADIUS server after seeing a RADIUS request from the AP.
Authentication Servers – An ordered list of authentication servers to be used
when clients attempt to authenticate through stateful 802.1x.
The equivalent CLI configuration for the example above is:
aaa stateful-authentication dot1x mode enable
aaa stateful-authentication dot1x timeout "20"
aaa stateful-authentication dot1x auth-server test
aaa mac-authentication max-authentication-failures 0
AP/Server Configuration
After enabling stateful 802.1x as shown above, a list of each third-party AP
for which stateful 802.1x should be performed must be entered as shown in
the figure below.