authentication mac-authentication lldp-override

Configures the switch to replace the authenticated MAC address on a FlexAuth-enabled port with the MAC address received in an LLDP frame.
Syntax
authentication mac-authentication lldp-override [ timeout seconds ]
no authentication mac-authentication lldp-override [ timeout seconds ]
Command Default

The default timeout for an LLDP packet to arrive is 30 seconds.

Parameters
timeout

Configures the timeout for MAC address authentication in LLDP packets.

seconds
Sets the timeout in seconds. The range is from 30 through 120.
Modes

Interface configuration mode

Usage Guidelines

This function is available only when FlexAuth and LLDP are enabled on the interface, and the port operates in multiple-hosts mode.

The override occurs if the LLDP packet arrives within the configured timeout (default: 30 seconds, configurable up to 120 seconds).

After initial MAC authentication, if the LLDP frame is received within the timeout, the switch authenticates the MAC address from the LLDP frame and updates the session. If the frame arrives after the timeout, the original authentication remains unchanged.

Note: Port-level configuration takes precedence over global settings.

If the timeout is not specified in the configuration, the system will default to 30 seconds.

Examples

The following example configures the MAC address of the received LLDP frame with a timeout value of 90 seconds to override the currently authenticated MAC address at the interface level on the FlexAuth port.

device# configure terminal
device(config)# interface ethernet 1/1/1
device(config-if-e10000-1/1/1)# auth auth-mode multiple-hosts
device(config-if-e10000-1/1/1)# authentication mac-authentication lldp-override timeout 90
History
Release version Command history
10.0.10h_cd1 This command was introduced.