Dell OS10 802.1X Port Authentication Configuration - 夜莺博客

Dell OS10 802.1X Port Authentication Configuration

802.1X on Dell PowerSwitch OS10 answers a specific compliance question: can an unauthorised device that plugs into a wall plate reach the network? A port that is not authenticated stays in an uncontrolled state and only EAPOL, CDP/LLDP and DHCP depending on configuration pass. This article covers the three moving parts on OS10 — the RADIUS server definition, the global dot1x system-auth-control switch, and the per-interface port control — plus the timers you will actually need to tune and the verification output that tells you whether a port is authorised.

RADIUS First

Nothing works until the switch can reach an authentication server. Define the server, then set retransmit and timeout so a dead RADIUS server fails predictably rather than hanging every port for the default period.

OS10(config)# radius-server host 10.10.1.200 key my-shared-secret
OS10(config)# radius-server retransmit 10
OS10(config)# radius-server timeout 10

The shared secret must match exactly on both sides; a trailing space pasted into the switch configuration is a surprisingly common cause of "the server rejects everything".

Enable 802.1X Globally

OS10(config)# dot1x system-auth-control

This is the master switch. With it disabled, per-interface dot1x commands have no effect and ports forward immediately — which is why audit tooling checks for its presence explicitly.

Configure Host-Facing Ports

OS10(config)# interface range ethernet 1/1/2-1/1/48
OS10(conf-range-eth1/1/2-1/1/48)# dot1x port-control auto
OS10(conf-range-eth1/1/2-1/1/48)# dot1x re-authentication

port-control auto puts the port under 802.1X control. dot1x re-authentication forces periodic revalidation instead of trusting the initial authentication forever, which is what closes the gap when a laptop is swapped for a device of the same identity.

Do not apply this to uplink ports. A port facing another switch normally has no supplicant, and putting it under port control is the fastest way to cut your own management path — use the console for the first deployment.

Timers and Behaviour Worth Knowing

  • Tx Period (default 30s) — how often EAPOL-Request/Identity is re-sent to a silent supplicant.
  • Quiet Period (default 60s) — how long the port stays silent after a failed authentication before it will accept EAPOL again.
  • Re-Auth Interval (default 3600s) — the re-authentication cycle when dot1x re-authentication is enabled.
  • Host Mode (default SINGLE_HOST) — one authenticated device per port. Change this only when you genuinely intend to allow a downstream switch or an IP phone plus a PC.
  • Auth-Fail VLAN / Guest VLAN — optional landing zones for devices that fail authentication, which turn a hard reject into a quarantine network.

Verification

OS10# show dot1x interface ethernet 1/1/1
OS10# show dot1x interface ethernet 1/1/1 statistics
OS10# show running-configuration dot1x

The per-interface output is where you confirm the state machine: Dot1x Status: Enable, Port Control: AUTO, and Port Auth Status flipping from UNAUTHORIZED to AUTHORIZED after a successful EAP exchange. If the PAE state sits in Initialize while a client is plugged in, the switch is not seeing EAPOL at all — check the client supplicant before touching the switch configuration.

Rollout Order

Deploy in monitor mode first where the platform supports it, or start with a single pilot switch and one VLAN. Confirm the RADIUS logs show successful Accepts, then expand by port range. Keep at least one port in the pilot switch outside port control so a mistake cannot lock you out of the management network.

Related topics on this site: Cisco 802.1X and MAB Configuration: Step-by-Step CLI Guide for the authentication-bypass variant used by printers and phones, ArubaOS-CX 802.1X Port Access: RADIUS, MAB and Roles for a cross-vendor syntax comparison, and RADIUS CoA and Disconnect-Message Configuration Guide for pushing a session change to a client without waiting for re-authentication.

原文链接:https://dell.com/support/manuals/en-my/smartfabric-os10-emp-partner/os10-sec-best-prac_rg/stig-compliance