authentication fail-action

Specifies the authentication failure action to move the client port to the restricted VLAN after authentication failure for both MAC authentication and 802.1X authentication on an interface.
Syntax
authentication fail-action restricted-vlan vlan-id
no authentication fail-action restricted-vlan
Command Default

The default action is to block the MAC address of the client.

Parameters
restricted-vlan
Specifies the failure action to move the client port to the restricted VLAN after authentication failure.
vlan-id
Specifies the ID of the VLAN to be configured as restricted VLAN.
Modes

Interface configuration mode

Usage Guidelines

If the authentication failure action is not configured, the client's MAC address is blocked in the hardware (default action) when the authentication fails.

The restricted VLAN specified at the interface level overrides the restricted VLAN configured using the restricted-vlan command at the global level. The configured restricted VLAN configured at the global level will still be applicable to other ports that don't have restricted VLAN configured at the interface level.

The client ports that were placed in the RADIUS-specified VLAN upon successful authentication are not placed in the restricted VLAN if the subsequent authentication fails. Instead, the non-authenticated client is blocked.

The no form of the command disables the authentication failure action.

Examples

The following example specifies authentication failure action to move the client port to the restricted VLAN (VLAN 4 is configured as restricted VLAN) after authentication failure.

device(config)# authentication
device(config-authen)# restricted-vlan 4
device(config-authen)# interface ethernet 1/1/1
device(config-if-e1000-1/1/1)# authentication fail-action restricted-vlan 5
History
Release version Command history
08.0.20 This command was introduced.