Switch CLI Reference Guide
- Introduction
- System Commands
- ACL Commands
- Domain Name Server (DNS) Commands
- Energy Efficient Ethernet (EEE) Commands
- Internet Group Management Protocol (IGMP) Commands
- IP Commands
- Link Aggregation Commands
- Loopback Detection Commands
- Link Layer Discovery Protocol Commands
- Monitor (Mirror) Commands
- Port-Based Network Access Control Commands
- Power Over Ethernet Commands
- Quality of Service Commands
- RADIUS Commands
- Remote Network Monitoring (RMON) Commands
- Simple Network Management Protocol (SNMP) Commands
- Simple Network Time Protocol (SNTP) Commands
- Spanning Tree Commands
- Secure Shell Commands
- Syslog Commands
- VLAN Commands
- Voice VLAN Commands
- SonicWall Support
Port-Based Network Access Control Commands
Command Objective |
This command enables dot1x in the Switch. The dot1x is an authentication mechanism. It acts as mediator between the authentication server and the supplicant (client). If the client accesses the protected resources, it contacts the authenticator with EAPOL frames. |
Syntax |
|
Mode | Global Configuration Mode |
Command Objective |
This command shuts down dot1x feature. By shutting down the dot1x feature, the supplicant-authenticator-authentication server architecture is dissolved. The data transport and authentication are directly governed by the authentication server/server. When shutdown, all resources acquired by dot1x module are released to the system. |
Syntax |
|
Mode | Global Configuration Mode |
Command Objective |
This command clears dot1x counters for all the ports on the Switch. |
Syntax |
|
Parameter Description |
|
Mode | Global Configuration Mode |
Command Objective |
This command enables/disables DoS prevention. |
Syntax |
|
Mode | Global Configuration Mode |
Command Objective |
This command configures Dot1x Guest VLAN ID. |
Syntax |
|
Parameter Description |
|
Mode | Global Configuration Mode |
Command Objective |
This command configures dot1x with default values for this port. The previous configurations on this port are reset to the default values. These details are not displayed but are the basic settings for a port. |
Syntax |
|
Mode | Interface Configuration Mode |
Command Objective |
This command sets the maximum number of EAP (Extensible Authentication Protocol) retries to the client by the authenticator before restarting authentication process. The count value ranges between 1 and 10. |
Syntax |
|
Mode | Interface Configuration Mode |
Command Objective |
This command sets the maximum number of EAPOL retries to the authenticator. The value range is 1 to 65535. |
Syntax |
|
Mode | Interface Configuration Mode |
Command Objective |
This command enables periodic re-authentication from authenticator to client. The periodic re-authentication is requested to ensure if the same supplicant is accessing the protected resources. The amount of time between periodic re- authentication attempts can be configured manually. |
Syntax |
|
Mode | Interface Configuration Mode |
Command Objective |
This command sets the dot1x timers. The timer module manages timers, creates memory pool for timers, creates timer list, starts and stops timer. It provides handlers to respective expired timers. |
Syntax |
|
Parameter Description |
|
Mode | Interface Configuration Mode |
Command Objective |
This command configures the authenticator port control parameter. The dot1x exercises port based authentication to increase the security of the network. The different Modes employed to the ports offer varied access levels. The 802.1x protocol is supported on both Layer 2 static-access ports and Layer 3 routed ports. |
Syntax |
|
Parameter Description |
|
Mode | Interface Configuration Mode |
Command Objective |
This command enables/disables guest-vlan feature. |
Syntax |
|
Mode | Interface Configuration Mode |
Command Objective |
This command displays dot1x information. The configured information can be viewed by running this show command. When there is any change in the configuration to ensure that the port is configured as desired, the show command is used. |
Syntax |
|
Parameter Description |
|
Mode | Privileged EXEC Mode |
Command Objective |
Displays dot1x Guest Vlan information. |
Syntax |
|
Mode | Privileged EXEC Mode |
Command Objective |
Displays Dos information. |
Syntax |
|
Mode | Privileged EXEC Mode |
Command Objective |
This command initiates re-authentication of all dot1x-enabled ports or the specified dot1x-enabled port. This initializes the state machines and sets up the environment for fresh authentication. Re-authentication is manually configured if periodic re- authentication is not enabled. Re-authentication is requested by the authentication server to the supplicant to furnish the identity without waiting for the configured number of seconds (re-authperiod). If no interface is specified, re-authentication is initiated on all dot1x ports. |
Syntax |
|
Parameter Description |
|
Mode | Privileged EXEC Mode |
Command Objective |
This command exits the current mode and reverts to the mode used prior to the current mode. |
Syntax |
|
Description |
This command exits the current mode and reverts to the mode used prior to the current mode. |
Mode | All |
Was This Article Helpful?
Help us to improve our support portal