Before authentication, the endpoint is unknown, and traffic is blocked. Upon authentication, the endpoint is known and traffic is allowed. The controller or service platform uses source MAC filtering to ensure that only the authenticated endpoint is allowed to send traffic.
To configure a device's wired 802.1x configuration:
Dot1x Authentication Control | Select this option to globally enable 802.1x authentication. 802.1x authentication is disabled by default. |
Dot1x AAA Policy | Select a AAA policy to associate with wired 802.1x traffic. If a suitable AAA policy does not exist, click the Create icon to create a new policy or the Edit icon to modify an existing policy. |
Dot1x Guest VLAN Control | Select this option to globally enable 802.1x guest VLANs for the selected device. This setting is disabled by default. |
MAC Authentication AAA Policy | Select a AAA authentication policy for MAC address authentication. If a suitable MAC AAA policy does not exist, click the Create icon to create a new policy or the Edit icon to modify an existing policy. |