show dot1x interface
Syntax
show dot1x interface
interface-name
<brief | detail | extensive>
Description
Display the current operational state of all ports with the list of connected users.
This command displays the list of connected supplicants received from the RADIUS authentication server regardless of the session state—that is, for both authenticated supplicants and for supplicants that attempted authentication.
Options
none | Display information for all authenticator ports. |
brief | detail | extensive | (Optional) Display the specified level of output. |
interface interface-name | (Optional) Display information for the specified interface with a list of connected supplicants. |
Required Privilege Level
view
Output Fields
Table 1 lists
the output fields for the show dot1x interface
command.
Output fields are listed in the approximate order in which they appear.
Field Name |
Field Description |
Level of Output |
---|---|---|
|
Name of a port. |
all |
|
The MAC address of the connected supplicant on the port. |
all |
|
The 802.1X authentication role of the interface. When 802.1X is enabled on an interface, the role is Authenticator. As Authenticator, the interface blocks LAN access until a supplicant is authenticated through 802.1X or MAC RADIUS authentication. |
|
|
The state of the port:
|
|
|
The username of the connected supplicant. |
|
|
The administrative state of the port:
|
|
|
The mode for the supplicant:
|
|
|
The number of seconds the port waits before reattempting authentication after a failed authentication exchange with the supplicant. |
|
|
The number of seconds the port waits before retransmitting the initial EAPOL PDUs to the supplicant. |
|
|
MAC RADIUS authentication:
|
|
|
MAC RADIUS authentication protocol:
|
|
|
The authentication method is restricted to MAC RADIUS. 802.1X authentication is not enabled. |
|
|
The reauthentication state:
|
|
|
The number of seconds the port waits for a response when relaying a request from the authentication server to the supplicant before resending the request. |
|
|
The number of seconds the port waits for a reply when relaying a response from the supplicant to the authentication server before timing out. |
|
|
The maximum number of times an EAPOL request packet is retransmitted to the supplicant before the authentication session times out. |
|
|
The number of non-802.1X clients granted access to the LAN by means of static MAC bypass. The following fields are displayed:
|
|
|
The VLAN to which a supplicant is connected when the supplicant is authenticated using a guest VLAN. If a guest VLAN is not configured on the interface, this field displays <not configured>. |
|
|
The behavior of the IEEE 802.1X clients when their MAC addresses age out:
|
|
|
The number of supplicants connected to a port. |
|
|
The username and MAC address of the connected supplicant. |
|
|
The authentication method used for a supplicant:
|
|
|
The VLAN to which the supplicant is connected. |
|
|
User policy filter sent by the RADIUS server. |
|
|
The configured GBP tag received by the Juniper-Switching-Filter VSA or the Juniper-Group-Based-Policy-Id VSA. |
|
|
The configured reauthentication interval. |
|
|
The number of seconds in which reauthentication occurs again for the connected supplicant. |
|
|
The number of seconds between interim RADIUS accounting messages. |
|
|
The number of seconds until the next interim RADIUS accounting update is due. |
|
|
The URL used to redirect the supplicant to a central Web server for authentication. |
|
Authenticated VoIP VLAN |
The VoIP VLAN to which the supplicant is connected. |
|
Sample Output
- show dot1x interface brief
- show dot1x interface detail (with GBP configured for QFX and EX switches)
- show dot1x interface extensive
show dot1x interface brief
user@host> show dot1x interface brief 802.1X Information: Interface Role State MAC address User ge-0/0/1 Authenticator Connecting 2001:db8:56:85:66:0F 00505685660f ge-0/0/2 Authenticator Authenticated 2001:db8:56:9E:56:42 0050569e5642
show dot1x interface detail (with GBP configured for QFX and EX switches)
user@host> show dot1x interface detail ge-0/0/0.0 Role: Authenticator Administrative state: Auto Supplicant mode: Single Number of retries: 3 Quiet period: 60 seconds Transmit period: 2 seconds Mac Radius: Enabled Mac Radius Restrict: Disabled Mac Radius Authentication Protocol: EAP-MD5 Reauthentication: Enabled Reauthentication interval: 120 seconds Supplicant timeout: 30 seconds Server timeout: 30 seconds Maximum EAPOL requests: 2 Guest VLAN member: not configured Retain mac aged session: Enabled Number of connected supplicants: 1 Supplicant: 001094001122, 00:10:94:00:11:22 Operational state: Authenticated Backend Authentication state: Idle Authentication method: Mac Radius Authenticated VLAN: VLAN_1 Group Based Policy Id: 100 Session Reauth interval: 120 seconds Reauthentication due in 51 seconds Eapol-Block: Not In Effect Domain: Data
user@host> show dot1x interface detail ge-0/0/0.0 Role: Authenticator Administrative state: Auto Supplicant mode: Multiple Number of retries: 3 Quiet period: 60 seconds Transmit period: 30 seconds Mac Radius: Enabled Mac Radius Restrict: Disabled Reauthentication: Enabled Configured Reauthentication interval: 30 seconds Supplicant timeout: 30 seconds Server timeout: 30 seconds Maximum EAPOL requests: 2 Guest VLAN member: not configured Retain mac aged session: Enabled Number of connected supplicants: 1 Supplicant: 00505685660f, 00:50:56:85:66:0F Operational state: Authenticated Backend Authentication state: Idle Authentication method: Server-Reject Vlan Authenticated VLAN: visitor-vlan Session Reauth interval: 30 seconds Reauthentication due in 20 seconds ge-0/0/1.0 Role: Authenticator Administrative state: Auto Supplicant mode: Multiple Number of retries: 3 Quiet period: 60 seconds Transmit period: 30 seconds Mac Radius: Enabled Mac Radius Restrict: Disabled Reauthentication: Enabled Configured Reauthentication interval: 30 seconds Supplicant timeout: 30 seconds Server timeout: 30 seconds Maximum EAPOL requests: 2 Guest VLAN member: not configured Number of connected supplicants: 1 Supplicant: 0050569e5642, 00:50:56:9E:56:42 Operational state: Authenticated Backend Authentication state: Idle Authentication method: Server-Reject Vlan Authenticated VLAN: visitor-vlan Session Reauth interval: 30 seconds Reauthentication due in 24 seconds
show dot1x interface extensive
user@host> show dot1x interface extensive 802.1X Information: Interface State MAC address Method Vlan User ge-0/0/6.0 Authenticated 2001:db8:94:00:00:01 Server-Reject Vlan 1400 Test12345
Release Information
Command introduced in Junos OS Release 15.1X49-D80.
extensive option introduced in Junos OS Release 19.4R1 to display
the additional fields when compared to brief option. The additional
fields are authentication method
and vlan-id
.
show dot1x interface detail (to check authenticated VoIP VLAN )
user@host> show dot1x interface detail ge-0/0/0.0 xe-0/0/37.0 Role: Authenticator Administrative state: Auto Supplicant mode: Multiple Number of retries: 3 Quiet period: 60 seconds Transmit period: 30 seconds Mac Radius: Enabled Mac Radius Restrict: Enabled Mac Radius Authentication Protocol: EAP-MD5 Reauthentication: Enabled Reauthentication interval: 3600 seconds Supplicant timeout: 30 seconds Server timeout: 30 seconds Maximum EAPOL requests: 2 Guest VLAN member: not configured Last Mac-Learn Request: 00:10:94:00:00:34 Last Mac-Learn Time: 2024-09-12 10:19:53.254451 Number of connected supplicants: 1 Supplicant: 001094000034, 00:10:94:00:00:34 Operational state: Authenticated Backend Authentication state: Idle Authentication method: Mac Radius Authenticated VLAN: vlan-10 Authenticated Voip VLAN: vlan-20 Session Reauth interval: 3600 seconds Reauthentication due in 3594 seconds Eapol-Block: Not In Effect Domain: Voip
user@host> show dot1x interface extensive 802.1X Information: Interface State MAC address Method Data Voip User vlan vlan xe-0/0/37.0 Authenticated 00:10:94:00:00:34 Mac Radius 10 20 001094000034