Authentication Client Timeout Scenarios (No Response to EAP Packets)
The dynamic VLAN assignment when the client does not respond to EAP packets is applicable only to 802.1X authentication. VLAN assignment when the client does not respond to the EAP packets depends on whether the authentication mode of the port is single untagged mode (the default) or multiple untagged mode.
- If there is no response from the client for EAP packets and if the guest VLAN is not configured, the behavior is the same as mentioned in Authentication failure scenarios.
- If the guest VLAN is configured:
- If it is the first client on the port, the client is authenticated in the guest VLAN.
- If the previous sessions are in a different RADIUS-assigned VLAN, the client is blocked.
- If the previous sessions are in the guest VLAN, the new client is permitted in the guest VLAN.
- If the previous sessions are in a critical VLAN or restricted VLAN, the client is blocked.
- If the previous sessions are in the guest VLAN and the new client is dot1x-capable, then existing guest MAC sessions are cleared before permitting the new client in the auth-default VLAN or RADIUS-assigned VLAN.
If there is no response from the client for EAP packets and if the guest VLAN is configured, the port is moved to the guest VLAN; otherwise, the failure action is carried out.