authentication fail-action

Specifies the authentication failure action to move the client port to the restricted VLAN after authentication failure for both MAC authentication and 802.1X authentication on an interface.
Syntax
authentication fail-action restricted-vlan { vlan-id } | permit
no authentication fail-action restricted-vlan { vlan-id } | permit
Command Default

The default action is to block the MAC address of the client.

Parameters
restricted-vlan
Specifies the failure action to move the client port to the restricted VLAN after authentication failure.
vlan-id
Specifies the ID of the VLAN to be configured as the restricted VLAN.
permit
Specifies that a failed authentication is logged, but the client placed in the default VLAN as a successful authentication.
Modes

Interface configuration mode

Usage Guidelines

If the authentication failure action is not configured, the client's MAC address is blocked in the hardware (default action) when the authentication fails.

Note: The authentication fail-action command takes effect only when Flexible authentication is enabled on the port. Therefore, Flexible authentication must be enabled on the port before the authentication failure action is configured for the port.

The authentication failure action can be configured globally or at the interface level. When both global and interface-level authentication failure actions are configured, the interface-level configuration takes precedence. The authentication failure action is configured at the global configuration level using the auth-fail-action command.

When the authentication fails and the permit action is configured, the attempt is logged as a failure but treated as a successful authentication, and the client is placed in the authentication default VLAN.

The restricted VLAN specified at the interface level overrides the restricted VLAN configured using the restricted-vlan command at the global configuration level. The restricted VLAN configured at the global level will still be applicable to other ports that do not have the restricted VLAN configured at the interface level.

The client ports that were placed in the RADIUS-specified VLAN upon successful authentication are not placed in the restricted VLAN if subsequent authentication fails. Instead, the non-authenticated client is blocked.

For additional guidelines, refer to "Data VLAN Requirements for Flexible Authentication" in the RUCKUS FastIron Security Configuration Guide.

The no form of the command disables the authentication failure action.

Examples

The following example specifies that the client port is moved to the restricted VLAN (VLAN 5 in the example) after an authentication failure.

device(config)# authentication
device(config-authen)# restricted-vlan 4
device(config-authen)# interface ethernet 1/1/1
device(config-if-e1000-1/1/1)# authentication fail-action restricted-vlan 5

The following example specifies that a failed authentication on interface 2/1/2 is logged, but the client is placed in the authentication default VLAN.

device(config)# authentication
device(config-authen)# interface ethernet 2/1/2
device(config-if-e1000-1/1/1)# authentication fail-action permit
History
Release version Command history
08.0.20 This command was introduced.
10.0.20 This command was updated to include the permit option.