Configuring An Authentication-Fail Vlan - Dell Force10 C150 Configuration Manual

Ftos configuration guide ftos 8.4.2.7 e-series terascale, c-series, s-series (s50/s25)
Hide thumbs Also See for Force10 C150:
Table of Contents

Advertisement

Configuring an Authentication-Fail VLAN

If the supplicant fails authentication, the authenticator re-attempts to authenticate after a specified amount of
time (30 seconds by default, see
can configure the maximum number of times the authenticator re-attempts authentication after a failure (3 by
default), after which the port is placed in the Authentication-fail VLAN.
Configure a port to be placed in the VLAN after failing the authentication process as specified number of
times using the command
the maximum number of authentication attempts by the authenticator using the keyword
this command.
Figure 7-13. Configuring an Authentication-fail VLAN
FTOS(conf-if-gi-1/2)#dot1x auth-fail-vlan 100 max-attempts 5
FTOS(conf-if-gi-1/2)#show config
!
interface GigabitEthernet 1/2
switchport
dot1x guest-vlan 200
dot1x auth-fail-vlan 100 max-attempts 5
no shutdown
View your configuration using the command
Figure
7-12, or using the command
Figure
7-14.
Figure 7-14.
FTOS(conf-if-gi-2/1)#dot1x port-control force-authorized
FTOS(conf-if-gi-2/1)#do show dot1x interface gigabitethernet 2/1
802.1x information on Gi 2/1:
-----------------------------
Dot1x Status:
Port Control:
Port Auth Status:
Re-Authentication:
Untagged VLAN id:
Guest VLAN:
Guest VLAN id:
Auth-Fail VLAN:
Auth-Fail VLAN id:
Auth-Fail Max-Attempts:
Tx Period:
Quiet Period:
ReAuth Max:
Supplicant Timeout:
Server Timeout:
Re-Auth Interval:
Max-EAP-Req:
Auth Type:
Auth PAE State:
Backend State:
122
|
802.1X
Configuring a Quiet Period after a Failed Authentication on page
dot1x auth-fail-vlan
show dot1x interface
Viewing Guest and Authentication-fail VLAN Configurations
Enable
FORCE_AUTHORIZED
UNAUTHORIZED
Disable
None
Enable
200
Enable
100
5
90 seconds
120 seconds
10
15 seconds
15 seconds
7200 seconds
10
SINGLE_HOST
Initialize
Initialize
from INTERFACE mode, as shown in
show config
from INTERFACE mode, as shown in
command from EXEC Privilege mode as shown in
114). You
Figure
7-13. Configure
max-attempts
with

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents