Authentication Timeout Action
A RADIUS timeout occurs when the ICX device does
not receive a response from a RADIUS server within a specified time and after a
certain
number of retries. The time limit and number of retries can be manually configured
using
the radius-server timeout
and radius-server
retransmit commands. If the parameters are not manually configured, the
ICX device applies the default value of 3 seconds with a maximum of 3 retries.
Administrators can control port behavior when a RADIUS timeout occurs by configuring a port on the ICX device to automatically pass or fail user authentication. A pass allows the client to continue with the VLAN and other policies. A fail blocks the client by default, unless a restricted VLAN or a default ACL is configured, in which case, the user is placed into a VLAN.
The following options are available:
- Failure (the default): This action blocks the client from accessing any network resource for a configured amount of time. If the failure action is configured as a restricted VLAN, the client is moved to the restricted VLAN.
- Success: The client is authenticated in the auth-default VLAN or in the previously
authenticated VLAN, depending on the following conditions:
- If RADIUS timeout occurs during the first authentication attempt, the client is authenticated in the auth-default VLAN.
- If the RADIUS timeout occurs during reauthentication of a previously authenticated client, the client is retained in the previously authenticated VLAN.
- If the RADIUS timeout occurs during the first authentication attempt, the client is authenticated in the critical VLAN.
- If the RADIUS timeout occurs during reauthentication of a previously authenticated client, the client is retained in the previously authenticated VLAN.
- Critical VLAN: The client is moved to a preconfigured critical VLAN. Any access policies applicable to that VLAN apply to this client.
Reauthentication for the timed out clients that
have been placed in the critical, restricted, or auth-default VLAN or the BLOCKED
state
(VLAN 4092) can be configured globally using the authentication reauth-timeout
command. By default, the timeout is enabled and is set to 300 seconds.