Cisco Wired Layer 2 Integration
Cisco Layer 2 switch configuration example.
In this example, a configuration validated on modern Cisco IOS-XE switches (Catalyst 9200 and 3850, IOS-XE 16.12+) is provided. Any Cisco Layer 2 switch supporting the following features is eligible for integration:
RADIUS Authentication/Accounting
802.1X
MAC Authentication Bypass (MAB)
RADIUS Change of Authorization (CoA)
Cisco-AVPair "url-redirect"
Cisco-AVPair "url-redirect-acl"
Note: In this example the NAC RADIUS Server / Policy Server is
10.10.10.10— replace this IP with the IP of your NAC system.Replace the VLAN number in the example port configuration with the desired default VLAN for the port.
The
radius server <name>block form shown below is used on IOS-XE 16.x and later. On older switches (IOS 15.2 and earlier) you may instead use the legacy single-line form:radius-server host 10.10.10.10 auth-port 1812 acct-port 1813 key XXXXX.
Layer 3 DHCP prerequisites
Layer 2 switch configuration
Note: The port configuration above attempts 802.1X first and falls back to MAB. On a port that serves only non-802.1X devices (printers, IP phones, IoT endpoints, etc.), the switch will wait for 802.1X to time out —
dot1x timeout tx-period× (dot1x max-reauth-req+ 1) seconds — before MAB authenticates the device. To avoid that delay on such ports, either:
remove the
dot1x pae authenticatoranddot1x ...lines so the port uses MAB only, orreverse the order so MAB is attempted first:
authentication order mab dot1x/authentication priority mab dot1x.
Additional ACL exceptions (if required)
Examples of other types of ACL exceptions that can be added to sc_quarantine_acl: