Dot1X Mac-Auth-Bypass; Dot1X Max-Eap-Req - Dell Force10 S4810P Reference Manual

Ftos command line reference guide for the s4810 system ftos 9.1.(0.0)
Hide thumbs Also See for Force10 S4810P:
Table of Contents

Advertisement

Usage
802.1X authentication is enabled when an interface is connected to the switch. If the host fails
Information
to respond within a designated amount of time, the authenticator places the port in the guest
VLAN.
If a device does not respond within 30 seconds, it is assumed that the device is not 802.1X
capable. Therefore, a guest VLAN is allocated to the interface and authentication for the
device occurs at the next re-authentication interval (dot1x reauthentication).
If the host fails authentication for the designated amount of times, the authenticator places the
port in authentication failed VLAN (dot1x auth-fail-vlan).
Related
dot1x auth-fail-vlan
Commands
dot1x reauthentication
show dot1x interface

dot1x mac-auth-bypass

Enable MAC authentication bypass. If 802.1X times out because the host did not respond to the Identity Request frame,
FTOS attempts to authenticate the host based on its MAC address.
C-Series, S-Series, Z-Series, S4810
Syntax
[no] dot1x mac-auth-bypass
Defaults
Disabled
Command Modes
INTERFACE
Command History
Version 8.3.11.4
Version 8.4.1.0
Usage
To disable MAC authentication bypass on a port, enter the no dot1x mac-auth-bypass
Information
command.

dot1x max-eap-req

Configure the maximum number of times an extensive authentication protocol (EAP) request is transmitted before the
session times out.
C-Series, E-Series, S-Series, Z-Series, S4810
Syntax
dot1x max-eap-req number
To return to the default, use the no dot1x max-eap-req command.
Parameters
number
1436
NOTE: The layer 3 portion of guest VLAN and authentication fail VLANs can be created
regardless if the VLAN is assigned to an interface or not. After an interface is assigned a
guest VLAN (which has an IP address), routing through the guest VLAN is the same as any
other traffic. However, the interface may join/leave a VLAN dynamically.
– configures a VLAN for authentication failures.
– enables periodic re-authentication.
– displays the 802.1X information on an interface.
Introduced on the Z9000.
Introduced on the C-Series and S-Series.
Enter the number of times an EAP request is transmitted before a
session time-out. The range is 1 to 10. The default is 2.

Advertisement

Table of Contents
loading

Table of Contents