SV-75285r1_rule
V-60829
SRG-NET-000338
AMLS-L2-000150
CAT II
10
Configure 802.1X on the switch, using the following mandatory parameters for all applicable interfaces. Replace the bracketed variable with the applicable value.
config
interface Ethernet[X]
switchport access vlan [Y]
dot1x pae authenticator
dot1x reauthentication
dot1x port-control auto
dot1x host-mode single-host
dot1x timeout quiet-period [value]
dot1x timeout reauth-period 3600
dot1x max-reauth-req [value]
For the global configuration, include the following command statements from the global configuration mode interface:
logging level DOT1X informational
aaa authentication dot1x default group radius
dot1x system-auth-control
This requirement only applies to devices required to employ 802.1X.
Verify the Arista Multilayer Switch re-authenticates 802.1X connected devices every hour. If the Arista Multilayer Switch does not re-authenticate 802.1X connected devices, this is a finding.
This can be viewed via the "show dot1x all" command. Under the interface configuration for the .1X connected port, the following statements must be present:
ReauthPeriod : 3600 seconds
If the device does not require re-authentication, or if the re-authentication period is longer than 60 minutes, this is a finding.
V-60829
False
AMLS-L2-000150
This requirement only applies to devices required to employ 802.1X.
Verify the Arista Multilayer Switch re-authenticates 802.1X connected devices every hour. If the Arista Multilayer Switch does not re-authenticate 802.1X connected devices, this is a finding.
This can be viewed via the "show dot1x all" command. Under the interface configuration for the .1X connected port, the following statements must be present:
ReauthPeriod : 3600 seconds
If the device does not require re-authentication, or if the re-authentication period is longer than 60 minutes, this is a finding.
M
2821