Source record · tier 2 current vendor documentation
Security Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9300 Switches) - Configuring IEEE 802.1x Port-Based Authentication
- Publisher
- Cisco Systems
- URL
- https://www.cisco.com/c/en/us/td/docs/switches/lan/catalyst9300/software/release/17-18/configuration_guide/sec/b_1718_sec_9300_cg/configuring_ieee_802_1x_port_based_authentication.html
- Published
- 2025-07-31
- Updated
- unknown
- Accessed
- 2026-10-02
- HTTP status
- 200
- License
- Cisco copyright; no-redistribution; short excerpts and locators only
Source notes citing this source
- The command authentication event server dead action authorize voice enables critical voice VLAN, which keeps voice devices on the voice VLAN when the RADIUS server is unreachable. in context
- In multidomain authentication a Catalyst switch identifies an authenticated device as a voice device only if the RADIUS server returns device-traffic-class=voice; without it the device is treated as a data device. in context
- Multidomain authentication allows one data device and one voice device on a port, each authenticated individually; a second device of the same class causes a security violation. in context
- When a port's host mode is multi-domain, the voice VLAN must be configured on the port with switchport voice vlan <vlan-id>. in context
- A non-ISE RADIUS server authenticating Cisco phones behind an MDA port must be configured to return the Cisco AV pair device-traffic-class=voice in its Access-Accept for the phone to reach the voice VLAN. inferred in context
- On Catalyst 9300 802.1X is globally disabled by default and ports default to force-authorized in single-host mode. in context
- The interface commands for an 802.1X phone port include authentication (or access-session) host-mode multi-domain, dot1x pae authenticator, mab as an optional fallback, and authentication (or access-session) port-control auto. in context
- show access-session and show authentication sessions display the 802.1X and MAB session state on a Catalyst switch port. in context
Cite this source record
APA
WarmTransfer. (2025, July 31). Security Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9300 Switches) - Configuring IEEE 802.1x Port-Based Authentication. WarmTransfer. https://warmtransfer.net/knowledge/sources/cisco-cat9300-1718-8021x-config
BibTeX
@misc{warmtransfer-cisco-cat9300-1718-8021x-config,
title = {Security Configuration Guide, Cisco IOS XE 17.18.x (Catalyst 9300 Switches) - Configuring IEEE 802.1x Port-Based Authentication},
author = {{WarmTransfer}},
year = {2025},
url = {https://warmtransfer.net/knowledge/sources/cisco-cat9300-1718-8021x-config},
note = {Cisco Systems, accessed 2026-10-02}
}