cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1989
Views
0
Helpful
1
Replies

802.1x vs Mac address filtering

jfraasch
Level 3
Level 3

We are looking at locking down access to our internal network. We want each device, not just user, authenticated to the network. I would prefer not to have to put a mac-address filter on each of my switches, we have over 200 of them. Is there a way for 802.1x to authenticate a device either with a software token, a certificate, or other means. I would prefer for the switch port authentication to be centrally managed rather than managed individually by each switch.

Thanks in advance for your help.

1 Reply 1

anar
Level 1
Level 1

You can do that by using the radius server.

On the switches you have to specify

aaa authentication dot1x default group radius

radius-server host x.x.x.x