cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
543
Views
0
Helpful
6
Replies

C1200 802.1x Missing Settings

eshaq786
Level 1
Level 1

I have a C1200-24P-4G switch. For some reason even though i have enabled advanced view on the GUI, I cannot see all the 802.1x settings that the admin guide refers to. For example, the options for MAB is missing. When i go to port authentication and edit a port, the options to enable 802.1x are not there. Is this a limitation or some other quirk? I am running firmware 4.1.7.24.

eshaq786_1-1768065037449.png

 

eshaq786_0-1768065008495.png

eshaq786_2-1768065122997.png

 

 

1 Accepted Solution

Accepted Solutions

Hi,

   MAB is not supported on CAT 1200 series, regardless on what documentation might state.

Thanks,

Cristian.

View solution in original post

6 Replies 6

pieterh
VIP
VIP

1) have you allready configured your reference to the  radiusserver ?
2) have you enabled AAA? ("aaa authentication enable")

The radius server is referenced and reports that its up.

dot1x system-auth-control is present which says its for "Enable or Disable Port-Based Network Access Control"

More worryingly is that MAB is not supported from what i can see on the available options for port config. 

back-pressure Enable back-pressure
bridge Bridge configuration subcommand
cdp CDP interface subcommands
channel-group Add port to Port-channel
description Interface specific description
do execute an EXEC-level command
dot1x Interface Configuration Commands for 802.1x
duplex Configure duplex operation
eee Energy Efficient Ethernet
end Exit from configure mode
exit Exit from current context
flowcontrol Configure flow-control mode
green-ethernet Green ethernet commands
gvrp GVRP interface commands
help Description of the interactive help system
ip IP commands
ipv6 Configure IPv6
lacp Interface IEEE 802.3 link aggregation commands
lldp Configure LLDP protocol
loopback-detection Enable loopback detection per interface
macro Ports macros
mdix Control cable crossover (MDI/MDIX)
negotiation Enable auto negotiation
no Negate command
operation port operation time command
port Set port definition
power Configure the administrative mode of the inline power
qos Configure Qos trust settings
rate-limit Use the rate-limit interface configuration command to
limit the rate of the incoming traffic. Use the no
form of this command to disable rate limit.
rmon Remote Monitoring (RMON) configuration subcommand
security-suite security protections
service-acl Apply an ACL to particular interface.
service-policy Apply a policy map to particular interface.Only one
policy map per interface per direction is supported.
shutdown Shutdown the selected interface
smartport Set of commands to be used only in smartport macros
snmp SNMP
sntp Global Simple Network Time Protocol (SNTP)
configuration subcommands
spanning-tree Spanning Tree Subsystem
speed Set the transmit and receive speeds
storm-control storm-control
surveillance-vlan Auto Surveillance VLAN configuration
switchport Configure switch port definition in vlan
traffic-shape Configure shaper on an egress port. Use the no form of
the command to disable the shaper.
voice Voice management.
SW01(config-if)#dot1x
control-direction Set the port control direction that defines which
traffic will be blocked on a port that is 802.1x
un-authorized
guest-vlan guest Vlan
host-mode Allow a single host (client) or multiple hosts on an
IEEE 802.1x-authorized port
max-hosts Maximum number of authenticated hosts allowed on the
interface
max-req Set the maximum number of times to send an EAP-request
before restarting the authentication process. (Change
the default value only to adjust for unusual
circumstances)
port-control Set the port-control value
reauthentication Enable or Disable Reauthentication for this port
timeout Set various timeouts
violation-mode Configure the action to be taken when violation is
detected

Hi,

   MAB is not supported on CAT 1200 series, regardless on what documentation might state.

Thanks,

Cristian.

Cisco should really correct their documentation or make it clearer if it only applies to certain models within the range.

Hi,

   Yes, we all can do better. The only true way to help is to open TAC case, ask them for confirmation and ask for documentation to be updated.

Thanks,

Cristian.

pieterh
VIP
VIP

look at this post
https://community.cisco.com/t5/switching/catalyst-1200-support-802-1x-mac-based-authentication/td-p/5202701
where "MAB not supported" is mentioned by multiple comuntity members, even verified by CiscoTAC.