Authentication Timeout Action
A RADIUS timeout occurs when the ICX device does not receive a response from a RADIUS
server within a specified time and after a certain number of retries. The time limit
and number of retries can be manually configured using the
radius-server timeout
and
radius-server retransmit
commands. If the parameters are not manually configured, the ICX device applies the
default value of 3 seconds with a maximum of 3 retries.
Administrators can control port behavior when a RADIUS timeout occurs by configuring a port on the ICX device to automatically pass or fail user authentication. A pass allows the client to continue with the VLAN and other policies. A fail blocks the client by default, unless a restricted VLAN or a default ACL is configured, in which case, the user is placed into a VLAN.
The following options are available:
- Failure (the default): This action blocks the client from accessing any network resource for a configured amount of time. If the failure action is configured as a restricted VLAN, the client is moved to the restricted VLAN.
- Success: The client is authenticated in the auth-default VLAN or in the previously
authenticated VLAN, depending on the following conditions:
- If RADIUS timeout occurs during the first authentication attempt, the client is authenticated in the auth-default VLAN.
- If the RADIUS timeout occurs during reauthentication of a previously authenticated client, the client is retained in the previously authenticated VLAN.
- If the RADIUS timeout occurs during the first authentication attempt, the client is authenticated in the critical VLAN.
- If the RADIUS timeout occurs during reauthentication of a previously authenticated client, the client is retained in the previously authenticated VLAN.
- Critical VLAN: The client is moved to a preconfigured critical VLAN. Any access policies applicable to that VLAN apply to this client.
Reauthentication for timed out clients that have
been placed in the critical, restricted, or auth-default VLAN or the BLOCKED state
(VLAN
4092) can be configured globally using the authentication reauth-timeout
command. By default, the timeout is enabled and is set to 300 seconds.