Authentication Timeout Action

A single authentication timeout action can be specified for MAC authentication and IEEE 802.1X authentication timeouts with the RADIUS server.

A RADIUS timeout occurs when the ICX device does not receive a response from a RADIUS server within a specified time and after a certain number of retries. The time limit and number of retries can be manually configured using the radius-server timeout and radius-server retransmit commands. If the parameters are not manually configured, the ICX device applies the default value of 3 seconds with a maximum of 3 retries.

Note: The radius-server retransmit command is not applicable to RADIUS server TLS connections.

Administrators can control port behavior when a RADIUS timeout occurs by configuring a port on the ICX device to automatically pass or fail user authentication. A pass allows the client to continue with the VLAN and other policies. A fail blocks the client by default, unless a restricted VLAN or a default ACL is configured, in which case, the user is placed into a VLAN.

The following options are available:

  • Failure (the default): This action blocks the client from accessing any network resource for a configured amount of time. If the failure action is configured as a restricted VLAN, the client is moved to the restricted VLAN.
  • Success: The client is authenticated in the auth-default VLAN or in the previously authenticated VLAN, depending on the following conditions:
    • If RADIUS timeout occurs during the first authentication attempt, the client is authenticated in the auth-default VLAN.
    • If the RADIUS timeout occurs during reauthentication of a previously authenticated client, the client is retained in the previously authenticated VLAN.
    • If the RADIUS timeout occurs during the first authentication attempt, the client is authenticated in the critical VLAN.
    • If the RADIUS timeout occurs during reauthentication of a previously authenticated client, the client is retained in the previously authenticated VLAN.
  • Critical VLAN: The client is moved to a preconfigured critical VLAN. Any access policies applicable to that VLAN apply to this client.
Note: Reauthentication is supported for auth-default, restricted, and critical VLANs. It is not supported for guest VLANs.
Note: The same VLAN can be specified as guest VLAN, restricted VLAN, and critical VLAN, if desired.

Reauthentication for the timed out clients that have been placed in the critical, restricted, or auth-default VLAN or the BLOCKED state (VLAN 4092) can be configured globally using the authentication reauth-timeout command. By default, the timeout is enabled and is set to 300 seconds.