Configuring Flexible Authentication Globally
- Enter the
configure terminalcommand to enter global configuration mode. - Enter the
authenticationcommand to enter authentication configuration mode.All the global authentication configurations are available in the authentication configuration mode. - (Optional) Enter the
auth-order mac-auth dot1xcommand to change the sequence of authentication methods to MAC authentication followed by 802.1X authentication if required.Note: If the 802.1X authentication and MAC authentication methods are enabled on the same port, by default, the authentication sequence is set to perform 802.1X authentication followed by MAC authentication. - Enter the
auth-default-vlancommand to configure the authentication default VLAN (auth-default VLAN).Note: The auth-default VLAN must be configured to enable Flexible authentication before enabling 802.1X authentication or MAC authentication.Note: Create the VLAN you plan to use before configuring it as the auth-default VLAN.Note: Ports that are members of the auth-default VLAN cannot be enabled for Flexible authentication. Likewise, ports that are enabled for Flexible authentication cannot be added manually to the auth-default VLAN.All ports are moved to the auth-default VLAN as MAC-VLAN members when 802.1X authentication or MAC authentication is enabled. The client remains in the auth-default VLAN if the RADIUS server does not return VLAN information upon authentication or if the RADIUS timeout action is specified as "success" when the RADIUS server is not reachable. - (Optional) Enter the
restricted-vlancommand to configure the restricted VLAN.When a restricted VLAN is configured, you can configure the authentication failure action as moving the client to the restricted VLAN. If a restricted VLAN is not configured, when authentication fails, the client's MAC address is blocked in the hardware. - (Optional) Enter the
auth-fail-actioncommand, followed by the desired authentication failure action. - (Optional) Enter the
critical-vlancommand to configure the VLAN in which the port should be placed when the RADIUS server times out while authenticating or reauthenticating. - (Optional) Enter the
auth-timeout-actioncommand to move the port to the critical VLAN after RADIUS authentication timeout. - (Optional) Enter the
auth-modecommand to enable multiple untagged mode, which allows Flexible authentication-enabled ports to be members of multiple untagged VLANs, or single-host and multiple-host mode.Note: By default, a Flexible authentication-enabled port can be a member of only one untagged VLAN (single-untagged mode), and other clients that are authenticated with different dynamic untagged VLANs are blocked. - (Optional) Enter the
disable-aging permitted-mac-onlycommand to prevent the permitted MAC sessions from being aged out. Or enter thedisable-aging denied-mac-onlyto prevent the denied MAC sessions from aging out.Note: You can disable aging of either the permitted (authenticated and restricted) sessions or the denied sessions. Once configured, MAC addresses that are authenticated or denied by a RADIUS server are not aged out if no traffic is received from the MAC address for a certain period of time. Aging for a permitted or non-blocked MAC address occurs in two phases, MAC aging and software aging. The MAC aging interval is configured using the
mac-age-timecommand. By default,mac-age-timeis set to 300 seconds. After the normal MAC aging period for permitted clients (or clients in a restricted VLAN), the software aging period begins. Themax-sw-agecommand is used to specify the software aging period and by default is set to 120 seconds. After the software aging period ends, the client session ages out and is removed from the session table.If during software aging, traffic is received from a client, the MAC address of the client is updated in the hardware table, and the client continues to communicate. Software aging is not applicable for blocked MAC addresses.
The hardware aging period for blocked MAC addresses is set to 70 seconds by default, and it can be configured using the
max-hw-agecommand. Once the hardware aging period ends, the blocked MAC address ages out and can be authenticated again if the ICX device receives traffic from the MAC address. - (Optional) Enter the
max-hw-agecommand to configure the hardware aging period for denied MAC addresses. - (Optional) Enter the
max-sw-agecommand to configure the software aging period. - (Optional) Enter the
max-sessionscommand to configure the number of clients allowed on a port, the default being 2. - (Optional) Enter the
re-authenticationcommand to configure the ICX device to periodically reauthenticate the authenticated clients. - (Optional) Enter the
reauth-periodcommand to configure the interval at which authenticated clients are reauthenticated. The default period is an hour, or 3600 seconds. - (Optional) Enter the
authentication reauth-timeoutcommand to configure the interval at which non-authenticated (timed out) clients with restricted, critical, or auth-default access are reauthenticated. The default period is 300 seconds.Note: Reauthentication is supported for restricted, critical access, and auth-default VLANs as well as the BLOCKED state VLAN (4092). It is not supported for guest access.Note: A session is moved to the BLOCKED state VLAN if the timeout-action is "failure" and no restricted VLAN has been configured. - (Optional) Specify the IPv4 or IPv6 ingress or egress ACLs to be applied when clients are non-authenticated for various reasons, such as auth-failure, auth-timeout, and access becomes restricted, critical, or guest. Authenticated clients can be assigned ACLs by the RADIUS server.
- (Optional) Specify the voice VLAN to be used to add the port as tagged in voice VLAN when it is not provided by the RADIUS server and when the clients are non-authenticated for various reasons, such as auth-failure and auth-timeout.