cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
615
Views
0
Helpful
4
Replies

802.1x backup solution for local AAA?

CSCO11733516
Level 1
Level 1

So I've decided to utilize 802.1x on a switch module on a 2901, reasons being for mobility for a laptop and network security.

However, the 802.1x authentication occurs over the VPN Tunnel (over the Internet).  What our concern is, what happens if the Internet or Tunnel goes down?  I know that 802.1x does not authenticate against the IOS local DB, so what would be another option in case this scenario happened?

There will only be one device authenticating (maybe 2) and they are 2 HP Windows 7 laptops.

Thanks in advance!

1 Accepted Solution

Accepted Solutions
4 Replies 4

shekharmore003
Level 1
Level 1

You can use following command.

authentication event server dead action reinitialize vlan (vlan-id)

This command means if the ISE server in not reachable then that perticular port of the switch fall in to the specified VLAN.

Shek-

  Thanks for the quick response, would that mean that no authentication would occur and the client would just be allowed to utilize the port on the specifiedVLAN?

Yes

CSCO11733516
Level 1
Level 1

Thanks for your help!

Sent from Cisco Technical Support iPhone App