11 Sept 2013

dot1x troubleshoot&view commands

show authentication sessions
show authentication interface XXX

show dot1x interface XXX


debug dot1x events
debug radius


A dot1x adventure...

802.1x

It's hell of an adventure, so strap your gas mask on and join me at the barricades!!

(article is wip, starting with notes first..)


Notes:

Use "Cisco-AV-Pair" parameter with value "device-traffic-class=voice" to make the switch put an IP Phone into a voice vlan.



1. host-mode selection





2. err-disable settings

authentication violation restrict|shutdown
 default is shutdown. i shall use restrict


3. re-auth & timers


inactivity timer (cisco default off)
  • Radius can return Idle-Timeout (in seconds)
  • Radius can return the action to take Termination-Action (I use Default which is reauth without service outage)
reauthentication interval 





I'll be using radius returned parameters for most of this.


 


4. critical AAA

5 Apr 2013

6500 Performance monitoring

Here are some commands to see stats/performance.



#show fabric utilization detail
  Fabric utilization:     Ingress                    Egress
    Module  Chanl  Speed  rate  peak                 rate  peak              
    1       0        20G    0%   18% @21:45 06Jan13    0%   15% @09:55 07Jan13
    1       1        20G    3%   10% @02:17 10Feb13    1%   10% @18:21 20Jul12
    2       0        20G    0%   10% @12:43 01Apr13    1%   16% @13:49 27Jan12
    2       1        20G    0%   11% @02:02 08Feb13    0%   10% @12:14 14Sep12
    3       0        20G    0%    9% @15:30 15Feb13    0%   98% @15:10 27Sep12
    3       1        20G    0%    9% @23:02 02Jun12    0%   97% @15:10 27Sep12
    5       0        20G    1%   54% @15:04 27Sep12    3%   49% @15:10 27Sep12
    5       1        20G    0%    0%                   0%    0%              
    7       0        20G    0%    6% @10:21 17Aug12    0%   17% @01:08 20Sep12
    7       1        20G    0%   49% @15:10 27Sep12    0%   53% @15:04 27Sep12

#

6500 Fabric Troubleshooting

Switch Fabric- Troubleshooting tips