Authentication Server Timeout Scenarios
VLAN assignment for RADIUS timeout cases depends on whether the authentication mode of the port is single untagged mode (the default) or multiple untagged mode. The authentication timeout action configured applies to MAC authentication and 802.1X authentication and can be one of the following actions:
A default ACL with IPv4 or IPv6 filters can also be configured to apply, if the timeout action is critical VLAN or Success.
Authentication timeout action depends on whether the authentication mode is single untagged mode or multiple untagged mode.
- If a RADIUS timeout action is not configured, the MAC session is cleared, and a new authentication is initiated.
- If an authentication timeout action is configured as "failure," the behavior is the same as mentioned in Authentication failure scenarios.
- If an authentication timeout action is configured as "success," the client is authenticated
in the auth-default VLAN or the previously authenticated VLAN, depending on the following
conditions:
- If a RADIUS timeout occurs during the first authentication attempt, the client is authenticated in the auth-default VLAN.
- If a RADIUS timeout occurs during reauthentication of a previously authenticated client, the client is retained in the previously authenticated VLAN with the existing dynamic ACL allocation. The VLAN can be either a dynamic untagged or tagged VLAN.
- If a RADIUS timeout action is configured as "critical-vlan," the action is implemented
based on the following conditions:
- If it is the first client authenticated on the port, the new client is authenticated in the critical VLAN.
- If the previous sessions are in the auth-default VLAN or RADIUS-assigned VLAN, the new client is blocked.
- If the previous sessions are in the restricted VLAN or guest VLAN, the MAC address is blocked.
- If the previous sessions are in the critical VLAN, the client is authenticated in the critical VLAN.
- If the RADIUS timeout occurs during reauthentication of a previously authenticated client, the client is retained in the previously authenticated VLAN with the existing dynamic ACL allocation. The VLAN can be either a dynamic untagged or tagged VLAN.
- If a RADIUS timeout action is not configured, the MAC session is cleared, and a new authentication is initiated.
- If a RADIUS timeout action is configured as "failure," the behavior is the same as mentioned in Authentication failure scenarios.
- If a RADIUS timeout action is configured as "success," the action is implemented based
on the following conditions:
- If a RADIUS timeout occurs during the first authentication attempt, the client is authenticated in the auth-default VLAN.
- If a RADIUS timeout occurs during reauthentication of a previously authenticated client, the client is retained in the previously authenticated VLAN with the existing dynamic ACL allocation. The VLAN can be either a dynamic untagged or tagged VLAN.
- For MAC authentication, if the authentication is initiated by a tagged packet, the client is authenticated in the VLAN ID carried by the packet tag value.
- If a RADIUS timeout action is configured as "critical-vlan," the action is implemented
based on the following conditions:
- The client is moved to the critical VLAN.
- If the RADIUS timeout occurs during reauthentication of a previously authenticated client, the client is retained in the previously authenticated VLAN with the existing dynamic ACL allocation. The VLAN can be either a dynamic untagged or tagged VLAN.
- For MAC authentication, if the authentication is initiated by a tagged packet, the client is blocked in the VLAN ID carried by the packet tag value.