beautypg.com

Brocade Multi-Service IronWare Security Configuration Guide (Supporting R05.6.00) User Manual

Page 340

background image

322

Multi-Service IronWare Security Configuration Guide

53-1003035-02

Displaying 802.1x information

8

Displaying information about the dot1x-mac-sessions
on each port

To display information about the dot1x-mac-sessions on each port on the device, enter the
following command.

Syntax: show dot1x mac-session [brief | [begin expression | exclude expression | include

expression]]

Table 52

describes the information displayed by the show dot1x mac-session command.

Displaying information about the ports in an 802.1x
multiple client configuration

To display information about the ports in an 802.1x multiple client configuration, enter the
following command.

TABLE 52

Output from the show dot1x mac-session command

This field...

Displays...

Port

The port on which the dot1x-mac-session exists.

MAC

The MAC address of the client

Username

The username used for RADIUS authentication.

Vlan

The VLAN to which the port is currently assigned.

Auth-State

The authentication state of the dot1x-mac-session. This can be one of the
following:
permit – The client has been successfully authenticated, and traffic from the
client is being forwarded normally.
blocked – Authentication failed for the client, and traffic from the client is being
dropped in hardware.
restricted – Authentication failed for the client, but traffic from the client is
allowed in the restricted VLAN only.
init - The client is in is in the process of 802.1x authentication, or has not
started the authentication process.

ACL

Whether or not an IP ACL is applied to incoming (i) and outgoing (o) traffic on
the interface

MAC

Whether or not a MAC filter is applied to the port.

Age

The software age of the dot1x-mac-session.

Brocade# show dot1x mac-session

Port MAC Username VLAN Auth State ACL|MAC Age

i|o|f

-------------------------------------------------------------------------------

1/1 0050.da0b.8cd7 Mary M 1 DENIED n|n|n 0

1/2 0050.da0b.8cb3 adminmorn 4094 PERMITTED y|n|n 0

1/3 0050.da0b.8bef reports 4094 PERMITTED y|n|n 0

1/4 0010.5a1f.6a63 testgroup 4094 PERMITTED y|n|n 0

1/5 0050.da1a.ff7e admineve 4094 PERMITTED y|n|n 0