auth-fail-action (Flexible Authentication)
auth-fail-action
restricted-vlan
[
voice
voice-vlan
]
no auth-fail-action
restricted-vlan
[
voice
voice-vlan
]
The MAC address of the client is blocked in the hardware.
Authentication configuration mode
auth-fail-action command takes effect only when flexible authentication is enabled on the ports. Therefore,
flexible authentication must be enabled on ports prior to configuring the authentication
failure action. The authentication failure action must also be reconfigured after
a change to the flexible authentication status of a port.
Before setting the authentication failure action to
restricted-vlan, the restricted VLAN must be configured using the
restricted-vlan command.
The authentication failure action can be configured globally or at the interface level.
When both global and interface-level authentication failure actions are configured,
the interface-level configuration takes precedence. Authentication failure action
is configured at interface level by using the
authentication fail-action command.
In single untagged mode, client ports that are placed in the RADIUS-specified VLAN upon successful authentication are not placed in the restricted VLAN when subsequent authentication fails. Instead, the non-authenticated client is blocked.
When voice VLAN is configured, clients are placed in the voice VLAN as a tagged member.
The
no form of the command removes the authentication failure action configuration.
The following example configures using VLAN 4 as the restricted VLAN and then specifies placing the client in the restricted VLAN after authentication failure.
device(config)# authentication device(config-authen)# restricted-vlan 4 device(config-authen)# auth-fail-action restricted-vlan
| Release version | Command history |
|---|---|
| 08.0.20 | This command was introduced. |
| 08.0.61 | This command was modified to support configuration of an authentication failure action for voice traffic. |