Specifications

Configuring and Managing Ports
4-4 Configuring and Managing Ports and VLANs
Example
Tosetport 1asawiredauthenticationport,typethefollowingcommand:
RBT-8100# set port type wired-auth 1
success: change accepted
Thiscommandconfiguresport1asawiredauthenticationportsupportingoneinterfaceandone
simultaneoususersession.
For802.1Xclients,wiredauthenticationworksonlyiftheclientsaredirectlyattachedtothewired
authenticationport,orareattachedthrou ghahubthatdoesnotblockforwardingofpacketsfrom
the
clienttothePAEgroupaddress(01:80:c2:00:00:03).Wiredauthenticationworksinaccordance
withthe802.1Xspecification,whichprohibitsaclientfromsendingtrafficdirectlytoan
authenticatorsMACaddressuntiltheclientisauthenticated.Insteadofsendingtraffictothe
authenticatorsMACaddress,theclientsendspacketstothePAE
groupaddress.The802.1X
specificationprohibitsnetworkingdevicesfromforwardingPAEgroupaddresspackets,because
thiswouldmakeitpossibleformultipleauthenticatorstoacquirethesameclient.
Fornon802.1Xclients,whouseMACauthentication,WebAAA,orlastresortauthentication,
wiredauthenticationworksiftheclientsaredirectlyattachedor
indirectlyattached.
Clearing a Port
Tochangeaport’stypefromDAPaccessportorwiredauthenticationport,youmustfirstclearthe
port,thensettheporttype.
Clearingaportremovesalltheport’sconfigurationsettingsandresetstheportasanetworkport.
•Iftheportisawiredauthenticatedport,clearingthe
portdisables802.1Xauthentication.
•Iftheportisanetworkport,theportmustfirstberemovedfromallVLANs,whichremove s
theportfromallspanningtrees,loadsharingportgroups,andsoon.
Toclearaport,usethefollowingcommand:
clear port type port-list
Note: If clients are connected to a wired authentication port through a downstream third-party
switch, the RoamAbout Switchattempts to authenticate based on any traffic coming from the switch,
such as Spanning Tree Protocol (STP) BPDUs. In this case, disable repetitive traffic emissions such
as STP BPDUs from downstream switches. If you want to provide a management path to a
downstream switch, use MAC authentication.
Note: When you clear a port, MSS ends user sessions that are using the port.
Note: A cleared port is not placed in any VLANs, not even the default VLAN (VLAN 1).