auth-fail-action (Flexible Authentication)

Configures, at a global level, the action taken after 802.1X and MAC authentication failure.
Syntax
auth-fail-action restricted-vlan [ voice voice-vlan ]
no auth-fail-action restricted-vlan [ voice voice-vlan ]
Command Default

The MAC address of the client is blocked in the hardware.

Parameters
restricted-vlan
Places the client in the restricted VLAN after authentication failure.
voice voice-vlan
Places the client in the voice VLAN after authentication failure.
Modes

Authentication configuration mode

Usage Guidelines
Note: The auth-fail-action command takes effect only when flexible authentication is enabled on the ports. Therefore, flexible authentication must be enabled on ports prior to configuring the authentication failure action. The authentication failure action must also be reconfigured after a change to the flexible authentication status of a port.

Before setting the authentication failure action to restricted-vlan, the restricted VLAN must be configured using the restricted-vlan command.

The authentication failure action can be configured globally or at the interface level. When both global and interface-level authentication failure actions are configured, the interface-level configuration takes precedence. Authentication failure action is configured at interface level by using the authentication fail-action command.

In single untagged mode, client ports that are placed in the RADIUS-specified VLAN upon successful authentication are not placed in the restricted VLAN when subsequent authentication fails. Instead, the non-authenticated client is blocked.

When voice VLAN is configured, clients are placed in the voice VLAN as a tagged member.

The no form of the command removes the authentication failure action configuration.

Examples

The following example configures using VLAN 4 as the restricted VLAN and then specifies placing the client in the restricted VLAN after authentication failure.

device(config)# authentication
device(config-authen)# restricted-vlan 4
device(config-authen)# auth-fail-action restricted-vlan

The following example specifies placing the client in the restricted VLAN and the voice VLAN after authentication failure.

device(config)# authentication
device(config-authen)# restricted-vlan 4
device(config-authen)# auth-fail-action restricted-vlan voice voice-vlan
History
Release version Command history
08.0.20 This command was introduced.
08.0.61 This command was modified to support configuration of an authentication failure action for voice traffic.