authentication fail-action
authentication
fail-action
restricted-vlan
{
vlan-id
}
|
permitno authentication
fail-action
restricted-vlan
{
vlan-id
}
|
permitThe default action is to block the MAC address of the client.
Interface configuration mode
If the authentication failure action is not configured, the client's MAC address is blocked in the hardware (default action) when the authentication fails.
authentication
fail-action command takes effect only when Flexible authentication is
enabled on the port. Therefore, Flexible authentication must be enabled on the
port
before the authentication failure action is configured for the port.The authentication failure action can be
configured globally or at the interface level. When both global and interface-level
authentication failure actions are configured, the interface-level configuration
takes precedence. The authentication failure action is configured at the global
configuration level using the auth-fail-action
command.
When the authentication fails and the permit action is configured, the attempt is logged as a failure but treated as a successful authentication, and the client is placed in the authentication default VLAN.
The restricted VLAN specified at the interface
level overrides the restricted VLAN configured using the restricted-vlan command
at the global configuration level. The restricted VLAN configured at the global
level will still be applicable to other ports that do not have the restricted
VLAN
configured at the interface level.
The client ports that were placed in the RADIUS-specified VLAN upon successful authentication are not placed in the restricted VLAN if subsequent authentication fails. Instead, the non-authenticated client is blocked.
For additional guidelines, refer to "Data VLAN Requirements for Flexible Authentication" in the RUCKUS FastIron Security Configuration Guide.
The
no form of the command disables the authentication failure action.
The following example specifies that the client port is moved to the restricted VLAN (VLAN 5 in the example) after an authentication failure.
device(config)# authentication device(config-authen)# restricted-vlan 4 device(config-authen)# interface ethernet 1/1/1 device(config-if-e1000-1/1/1)# authentication fail-action restricted-vlan 5