auth-timeout-action

Configures, at a global level, the action taken when external server authentication times out.
Syntax
auth-timeout-action { critical-vlan [ voice voice-vlan ] | failure | success }
no auth-timeout-action { critical-vlan [ voice voice-vlan ] | failure | success }
Command Default

Authentication timeout action is not configured at a global level.

Parameters
critical-vlan
Places the client in the critical VLAN after RADIUS timeout.
voice voice-vlan
Places the client in the voice VLAN after RADIUS timeout.
failure
Specifies that RADIUS timeout causes authentication failure.
success
Specifies that RADIUS timeout causes authentication success.
Modes

Authentication configuration mode

Usage Guidelines
Note: The auth-timeout-action command takes effect only when flexible authentication is enabled on the ports. Therefore, flexible authentication must be enabled on ports prior to configuring the RADIUS timeout action. The RADIUS timeout action must also be reconfigured after a change to the flexible authentication status of a port.

The auth-timeout-action command configures the RADIUS timeout action at a global level.

The success option triggers authentication success and the client is placed in the previously-authenticated VLAN. In the case of first time authentication, the client is placed in the default voice VLAN.

The failure option causes authentication failure and results in the execution of the authentication failure action. The authentication failure action is configured at a global level by using the auth-fail-action command and at the local interface level by using the authentication command.

RADIUS timeout action can also be configured at the port level by using the authentication timeout-action command. When authentication timeout actions are configured at both global and local port level, the port-level configuration takes precedence.

The no form of the command removes the authentication timeout action configuration.

Examples

The following example specifies placing the client in the critical VLAN and the voice VLAN (for voice traffic) after RADIUS authentication timeout.

device# configure terminal
device(config)# authentication
device(config-authen)# auth-timeout-action critical-vlan voice voice-vlan
History
Release version Command history
08.0.61 This command was introduced.