aaa authentication port-access dot1x authenticator
802.1X, switch-wide
Global switch for 802.1X plus the RADIUS group it uses. It needs enable here and on each port: either one off and nothing authenticates.
In every release here, 10.15 to 10.18.
try it in the sandbox
aaa authentication port-access dot1x authenticatorradius server-group CLEARPASSenableinterface 1/1/1-1/1/8aaa authentication port-access dot1x authenticatorenable
Goes withaaa authentication port-access mac-authshow port-access clients
aaa authentication port-access mac-auth
MAC authentication, switch-wide
The same pattern as 802.1X: a global block with the group and enable, and enable per port. The switch sends the MAC as username and password, 00005e005305 style by default.
In every release here, 10.15 to 10.18.
try it in the sandbox
aaa authentication port-access mac-authradius server-group CLEARPASSenableinterface 1/1/5aaa authentication port-access mac-authenable
aaa authentication port-access client-limit <1-256>
How many clients a port takes
One by default. A PC behind a phone needs two, or a multi-domain port. Only clients that got in take a place.
In every release here, 10.15 to 10.18.
Changed: 10.18 added client-limit device-mode <n> on the port and in a role.
try it in the sandbox
interface 1/1/3aaa authentication port-access client-limit 2
aaa authentication port-access auth-precedence <order>
Which method goes first
dot1x then mac-auth is the default. A device with no supplicant waits out the 802.1X timeout before MAC auth starts; mac-auth first is faster for printers and slower for laptops.
In every release here, 10.15 to 10.18.
try it in the sandbox
interface 1/1/5aaa authentication port-access auth-precedence mac-auth dot1xinterface 1/1/1aaa authentication port-access auth-precedence dot1x mac-auth
aaa authentication port-access critical-role <WORD>
A role when RADIUS is down
If every RADIUS server times out, clients get this role instead of nothing. reject-role is the same for a reject.
In every release here, 10.15 to 10.18.
Habit: Decide what a building does when ClearPass is unreachable before it happens. Critical role is that decision written down.
try it in the sandbox
interface 1/1/1aaa authentication port-access critical-role QUARANTINEinterface 1/1/1aaa authentication port-access reject-role GUEST
aaa authentication port-access auth-mode multi-domain
A phone and a PC on one port
One voice device and one data device (client-limit multi-domain raises the data count). The voice device is whoever holds a role with device-traffic-class voice.
In every release here, 10.15 to 10.18.
try it in the sandbox
interface 1/1/6aaa authentication port-access auth-mode multi-domaininterface 1/1/6aaa authentication port-access client-limit multi-domain 2
Goes withdevice-traffic-class voiceaaa authentication port-access allow-lldp-bpdu
aaa authentication port-access allow-lldp-bpdu
Hear LLDP before authentication
A port-access port drops LLDP from a client that has not authenticated. A phone that never authenticates is then invisible to LLDP, its device profile never matches, and it gets no voice VLAN. This lets LLDP through. Found the hard way on the lab switch on 2026-09-28.
In every release here, 10.15 to 10.18.
Changed: 10.17 added aaa authentication port-access lldp-loop-guard enable beside it.
try it in the sandbox
interface 1/1/6aaa authentication port-access allow-lldp-bpdu
Goes withdebug <portaccess|radius|lldp> <what>
port-access role <WORD>
A local user role
What a client gets once it is in: an access VLAN, or a native VLAN and a tagged list, and more on 10.18. RADIUS names the role; the switch must have it or the client fails authorization.
In every release here, 10.15 to 10.18.
Changed: 10.18 added speed, voice-vlan, stp-bpdu-guard, rate-limits, toggle-link and client-limit device-mode to a role.
try it in the sandbox
port-access role EMPLOYEEvlan access 10port-access role AP-TRUNKvlan trunk native 99vlan trunk allowed 10,20,99
Goes withshow port-access role
device-traffic-class voice
This role is the voice device
On a multi-domain port the client holding this role is the voice device. Pair it with a native data VLAN and the voice VLAN tagged.
In every release here, 10.15 to 10.18.
try it in the sandbox
port-access role VOICEdevice-traffic-class voicevlan trunk native 10vlan trunk allowed 30
show port-access clients
Who is on and how
One line per client: port, name, role, VLAN, and four flags: how it got in (1x, ma, dp), mode (c, d, m), device type (d, v) and status (s, f, p). --|c|-|f is a failure. Add detail for the history, interface, mac or role to filter.
In every release here, 10.15 to 10.18.
Habit: Read Auth History in the detail view bottom to top: it is the order things happened.
try it in the sandbox
show port-access clientsshow port-access clients interface 1/1/6 detailshow port-access clients onboarding-method device-profile
show aaa authentication port-access interface all client-status
Client status, compact
The authentication and authorization blocks for every client, without VLAN and MACsec detail.
In every release here, 10.15 to 10.18.
try it in the sandbox
show aaa authentication port-access interface all client-statusshow aaa authentication port-access interface 1/1/1 client-status
show port-access role
The roles and what they carry
Each local role: VLANs, device type, gateway zone. show port-access role name X for one.
In every release here, 10.15 to 10.18.
try it in the sandbox
show port-access roleshow port-access role name VOICE
port-access reauthenticate interface <IFNAME>
Make clients authenticate again
10.18 has no clear port-access clients. To start clients over: reauthenticate a port, or log one off by MAC, port or role.
In every release here, 10.15 to 10.18.
try it in the sandbox
port-access reauthenticate interface 1/1/1port-access log-off client mac 00:00:5e:00:53:01port-access log-off client role GUEST
port-access fallback-role <WORD>
A role for whatever is on the port
The role a client gets when nothing else gives it one. With no authentication on the port that is everything plugged in: with a gateway zone in the role, that is port-based tunnelling.
In every release here, 10.15 to 10.18.
try it in the sandbox
interface 1/1/4port-access fallback-role PBT-IOT