auth-fail-action (Flexible Authentication)
auth-fail-action
restricted-vlan
[
voice
voice-vlan
]
|
permitno auth-fail-action
restricted-vlan
[
voice
voice-vlan
]
|
permitThe MAC address of the client is blocked in the hardware.
Authentication configuration mode
auth-fail-action
command takes effect only when Flexible authentication is enabled on the ports.
Therefore, Flexible authentication must be enabled on ports before the
authentication failure action is configured.When the authentication fails and the permit action is configured, the attempt is logged as a failure but treated as a successful authentication, and the client is placed in the authentication default VLAN.
Before setting the authentication failure action to
restricted-vlan, the restricted VLAN must be configured using the
restricted-vlan command.
The authentication failure action can be
configured globally or at the interface level. When both global and interface-level
authentication failure actions are configured, the interface-level configuration
takes precedence. The authentication failure action is configured at the interface
level using the authentication fail-action command.
In single untagged mode, client ports that are placed in the RADIUS-specified VLAN upon successful authentication are not placed in the restricted VLAN when subsequent authentication fails. Instead, the non-authenticated client is blocked.
In single untagged mode with the authentication fail-action configured as permit, successfully authenticated client ports are placed in the RADIUS-specified VLAN. Any subsequent failed clients are placed in the same RADIUS-returned VLAN as clients on the same port that were successfully authenticated.
When voice VLAN is configured, clients are placed in the voice VLAN as a tagged member.
For additional guidelines, refer to "Data VLAN Requirements for Flexible Authentication" in the RUCKUS FastIron Security Configuration Guide.
The
no form of the command removes the authentication failure action configuration.
The following example configures VLAN 4 as the restricted VLAN and specifies that the client is placed in the restricted VLAN after authentication failure.
device(config)# authentication device(config-authen)# restricted-vlan 4 device(config-authen)# auth-fail-action restricted-vlan
The following example specifies that the client is placed in the restricted VLAN and the voice VLAN after authentication failure.
device(config)# authentication device(config-authen)# restricted-vlan 4 device(config-authen)# auth-fail-action restricted-vlan voice voice-vlan