authentication timeout-action

Configures the authentication timeout actions to specify the action for the RADIUS server if an authentication timeout occurs.
Syntax
authentication timeout-action { success | failure | critical-vlan }
no authentication timeout-action { success | failure | critical-vlan vlan-id }
Command Default

The default authentication timeout action is failure.

Parameters
success
Considers the client as authenticated after RADIUS timeout. After the timeout action is enabled as success, use the no form of the command to set the RADIUS timeout behavior to retry.
failure
Specifies the RADIUS timeout action to carry out the configured failure action. If the failure action is not configured, the client's MAC address is blocked in the hardware. Once the failure timeout action is enabled, use the no form of the command to reset the RADIUS timeout behavior to retry.
critical-vlan
On initial authentication, specifies that the client be moved to the client to the designated critical VLAN after authentication timeout. This command applies only to data traffic.
vlan-id
Specifies the ID of the VLAN to be configured as critical VLAN.
Modes

Interface configuration mode

Usage Guidelines

The no form of this command will disable this functionality.

If the timeout is configured as success, client will be authenticated in the auth-default VLAN.

If the authentication failure action is configured as restricted VLAN using the authentication fail-action command, the client is placed in the restricted VLAN. A restricted VLAN must be configured using the restricted-vlan command at the global level or using the authentication fail-action restricted-vlan command at the interface level.

The critical VLAN specified at the interface level overrides the critical VLAN configured using the critical-vlan command at the global level. The configured critical VLAN configured at the global level will still be applicable to other ports that don't have critical VLAN configured at the interface level.

Examples

The following example sets the authentication timeout-action command to success.

device(config)# authentication
device(config)# interface ethernet 1/1/1 
device(config-if-e1000-1/1/1)# authentication timeout-action success
History
Release version Command history
08.0.20 This command was introduced.