auth-fail-action (Flexible Authentication)

Configures, at a global level, the action taken after 802.1X and MAC authentication failure.
Syntax
auth-fail-action restricted-vlan [ voice voice-vlan ] | permit
no auth-fail-action restricted-vlan [ voice voice-vlan ] | permit
Command Default

The MAC address of the client is blocked in the hardware.

Parameters
restricted-vlan
Places the client in the restricted VLAN after authentication failure.
voice voice-vlan
Places the client in the voice VLAN after authentication failure.
permit
Specifies that a failed authentication is logged, but the client is placed in the default VLAN as a successful authentication.
Modes

Authentication configuration mode

Usage Guidelines
Note: The auth-fail-action command takes effect only when Flexible authentication is enabled on the ports. Therefore, Flexible authentication must be enabled on ports before the authentication failure action is configured.

When the authentication fails and the permit action is configured, the attempt is logged as a failure but treated as a successful authentication, and the client is placed in the authentication default VLAN.

Before setting the authentication failure action to restricted-vlan, the restricted VLAN must be configured using the restricted-vlan command.

The authentication failure action can be configured globally or at the interface level. When both global and interface-level authentication failure actions are configured, the interface-level configuration takes precedence. The authentication failure action is configured at the interface level using the authentication fail-action command.

In single untagged mode, client ports that are placed in the RADIUS-specified VLAN upon successful authentication are not placed in the restricted VLAN when subsequent authentication fails. Instead, the non-authenticated client is blocked.

In single untagged mode with the authentication fail-action configured as permit, successfully authenticated client ports are placed in the RADIUS-specified VLAN. Any subsequent failed clients are placed in the same RADIUS-returned VLAN as clients on the same port that were successfully authenticated.

When voice VLAN is configured, clients are placed in the voice VLAN as a tagged member.

For additional guidelines, refer to "Data VLAN Requirements for Flexible Authentication" in the RUCKUS FastIron Security Configuration Guide.

The no form of the command removes the authentication failure action configuration.

Examples

The following example configures VLAN 4 as the restricted VLAN and specifies that the client is placed in the restricted VLAN after authentication failure.

device(config)# authentication
device(config-authen)# restricted-vlan 4
device(config-authen)# auth-fail-action restricted-vlan

The following example specifies that the client is placed in the restricted VLAN and the voice VLAN after authentication failure.

device(config)# authentication
device(config-authen)# restricted-vlan 4
device(config-authen)# auth-fail-action restricted-vlan voice voice-vlan

The following example specifies that a failed authentication is logged but that the client is placed in the authentication default VLAN.

device(config)# authentication
device(config-authen)# auth-fail-action permit
History
Release version Command history
08.0.20 This command was introduced.
08.0.61 This command was modified to support configuration of an authentication failure action for voice traffic.
10.0.20 This command was updated to include the permit option.