Authentication Server Timeout Scenarios

VLAN assignment for RADIUS timeout cases depends on whether the authentication mode of the port is single untagged mode (the default) or multiple untagged mode. The authentication timeout action configured applies to MAC authentication and 802.1X authentication and can be one of the following actions:

  • Retry
  • Failure
  • Success
  • Move the client to a critical VLAN

A default ACL with IPv4 or IPv6 filters can also be configured to apply, if the timeout action is critical VLAN or Success.

Note: For the default ACL to work, a valid and defined ACL must be configured. Deleting the default ACL may result in unpredictable behavior. Dynamic modification of a default ACL is not supported. If changes must be made to the default ACL, clear all the existing sessions after the modifications are complete.

Note: For the dynamic ACL to work, a valid and defined ACL must be configured; otherwise, the session will be blocked. Deleting the dynamic ACL or any filter may result in unpredictable behavior. Dynamic modification to a dynamic ACL is not supported. If changes must be made to the dynamic ACL, clear all the applicable sessions after the modifications are complete. These actions should not affect other sessions or features.

Authentication timeout action depends on whether the authentication mode is single untagged mode or multiple untagged mode.

Single Untagged Mode

  • If a RADIUS timeout action is not configured, the MAC session is cleared, and a new authentication is initiated.
  • If an authentication timeout action is configured as "failure," the behavior is the same as mentioned in Authentication failure scenarios.
  • If an authentication timeout action is configured as "success," the client is authenticated in the auth-default VLAN or the previously authenticated VLAN, depending on the following conditions:
    • If a RADIUS timeout occurs during the first authentication attempt, the client is authenticated in the auth-default VLAN.
    • If a RADIUS timeout occurs during reauthentication of a previously authenticated client, the client is retained in the previously authenticated VLAN with the existing dynamic ACL allocation. The VLAN can be either a dynamic untagged or tagged VLAN.
  • If a RADIUS timeout action is configured as "critical-vlan," the action is implemented based on the following conditions:
    • If it is the first client authenticated on the port, the new client is authenticated in the critical VLAN.
    • If the previous sessions are in the auth-default VLAN or RADIUS-assigned VLAN, the new client is blocked.
    • If the previous sessions are in the restricted VLAN or guest VLAN, the MAC address is blocked.
    • If the previous sessions are in the critical VLAN, the client is authenticated in the critical VLAN.
    • If the RADIUS timeout occurs during reauthentication of a previously authenticated client, the client is retained in the previously authenticated VLAN with the existing dynamic ACL allocation. The VLAN can be either a dynamic untagged or tagged VLAN.

Multiple Untagged Mode

  • If a RADIUS timeout action is not configured, the MAC session is cleared, and a new authentication is initiated.
  • If a RADIUS timeout action is configured as "failure," the behavior is the same as mentioned in Authentication failure scenarios.
  • If a RADIUS timeout action is configured as "success," the action is implemented based on the following conditions:
    • If a RADIUS timeout occurs during the first authentication attempt, the client is authenticated in the auth-default VLAN.
    • If a RADIUS timeout occurs during reauthentication of a previously authenticated client, the client is retained in the previously authenticated VLAN with the existing dynamic ACL allocation. The VLAN can be either a dynamic untagged or tagged VLAN.
    • For MAC authentication, if the authentication is initiated by a tagged packet, the client is authenticated in the VLAN ID carried by the packet tag value.
  • If a RADIUS timeout action is configured as "critical-vlan," the action is implemented based on the following conditions:
    • The client is moved to the critical VLAN.
    • If the RADIUS timeout occurs during reauthentication of a previously authenticated client, the client is retained in the previously authenticated VLAN with the existing dynamic ACL allocation. The VLAN can be either a dynamic untagged or tagged VLAN.
    • For MAC authentication, if the authentication is initiated by a tagged packet, the client is blocked in the VLAN ID carried by the packet tag value.