Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

Dot1x

I want to configure our network for switch port authentication using 802.x.

I want to configure dot1x with authentication to wondows 2003 Radius.

I have 1 core switch C3750G router and other secondray switches C2960 connected to the core switch.

I want separate alle authenticated user to  be connected VLAN 1 and oud guest to guest to VLAN 2 for internet.

Do i have to configure only the core switch with dot1x and aaa authentication or all switches ( core and secondarY)

Thank you and kind regards,

1 ACCEPTED SOLUTION

Accepted Solutions
Hall of Fame Super Blue

Re: Dot1x

access1097BA wrote:

Thank verry kind of you,

Do i have to create also on all switches the Guest VLAN?

Where i have to do the routing to the internet Gateway voor the Guest Vlan?

If i enable the VTP than is that correct that i have to configure only ONE switch and the configuration will be propogate to the other switches>

Thank you verry much,

The Guest vlan will be needed on all switches that the guest traffic has to pass through to get to the Internet gateway.

Yes, if you make your core switch a VTP server and the 2960s VTP clients you can create the vlans on the core switch and they will be propogated to the 2960s.

Jon

7 REPLIES
Hall of Fame Super Blue

Re: Dot1x

access1097BA wrote:

I want to configure our network for switch port authentication using 802.x.

I want to configure dot1x with authentication to wondows 2003 Radius.

I have 1 core switch C3750G router and other secondray switches C2960 connected to the core switch.

I want separate alle authenticated user to  be connected VLAN 1 and oud guest to guest to VLAN 2 for internet.

Do i have to configure only the core switch with dot1x and aaa authentication or all switches ( core and secondarY)

Thank you and kind regards,

You need to configure all switches that have devices connected to them that you want to have 802.1x authentcation for. So if you have devices/users on the 2960 switches that you want to authenticate you will need dot1x configured on the 2960 switches.

Note, that if you no end users/devices on the core switch then you do not need dot1x config on core switch.

Jon

New Member

Re: Dot1x

Thank you for the answer,

Wat about the radius configuration on the switch, do i have also to enable it on all connected switches.

If i understand goed i don't need to do no configuration on the core switch.

Thanks alotb

Hall of Fame Super Blue

Re: Dot1x

access1097BA wrote:

Thank you for the answer,

Wat about the radius configuration on the switch, do i have also to enable it on all connected switches.

If i understand goed i don't need to do no configuration on the core switch.

Thanks alotb

On any switch that has a device/user you want to authenticate you will need to configure dot1x and also radius configuration ie. any switch doing dot1xauthentication will need to know which radius server(s) to talk to.

Jon

New Member

Re: Dot1x

Thank verry kind of you,

Do i have to create also on all switches the Guest VLAN?

Where i have to do the routing to the internet Gateway voor the Guest Vlan?

If i enable the VTP than is that correct that i have to configure only ONE switch and the configuration will be propogate to the other switches>

Thank you verry much,

Hall of Fame Super Blue

Re: Dot1x

access1097BA wrote:

Thank verry kind of you,

Do i have to create also on all switches the Guest VLAN?

Where i have to do the routing to the internet Gateway voor the Guest Vlan?

If i enable the VTP than is that correct that i have to configure only ONE switch and the configuration will be propogate to the other switches>

Thank you verry much,

The Guest vlan will be needed on all switches that the guest traffic has to pass through to get to the Internet gateway.

Yes, if you make your core switch a VTP server and the 2960s VTP clients you can create the vlans on the core switch and they will be propogated to the 2960s.

Jon

New Member

Re: Dot1x

Hi Jon,

Please can you help me further,

Can you please tel me step by step how i have to do this configuration.

Core switch 3750G, router and all my secondary 2960 switches are connected to the core switch.

I want all my local users authenticate to Radius for authentication.

I want to create a VLAN for local users and VLAN for guest internet.

Where and how i have to configure the dot1x ( on all example wat i found on google Fasteethernet0/3).

Waht they meen with fastethernet0/3, do i have to set the dot1x on alle switches port fastethernet0/3?

Please can you guide me.

Thanks

New Member

Re: Dot1x

Thank you verry much, i will try monday

the configuration and will let you know.

Kind regards,

824
Views
0
Helpful
7
Replies
CreatePlease login to create content