18.10.2013 Views

FTOS Command Reference for the S-Series - Force10 Networks

FTOS Command Reference for the S-Series - Force10 Networks

FTOS Command Reference for the S-Series - Force10 Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

dot1x max-eap-req<br />

Related<br />

<strong>Command</strong>s<br />

If a device does not respond within 30 seconds, it is assumed that <strong>the</strong> device is not 802.1x<br />

capable. There<strong>for</strong>e, a guest VLAN is allocated to <strong>the</strong> interface and au<strong>the</strong>ntication, <strong>for</strong> <strong>the</strong><br />

device, will occur at <strong>the</strong> next re-au<strong>the</strong>ntication interval (dot1x reau<strong>the</strong>ntication).<br />

If <strong>the</strong> host fails au<strong>the</strong>ntication <strong>for</strong> <strong>the</strong> designated amount of times, <strong>the</strong> au<strong>the</strong>nticator places <strong>the</strong><br />

port in au<strong>the</strong>ntication failed VLAN (dot1x auth-fail-vlan).<br />

dot1x max-eap-req<br />

c e s Configure <strong>the</strong> maximum number of times an EAP (Extensive Au<strong>the</strong>ntication Protocol)<br />

request is transmitted be<strong>for</strong>e <strong>the</strong> session times out.<br />

Syntax dot1x max-eap-req number<br />

Parameters<br />

Defaults 2<br />

<strong>Command</strong> Modes INTERFACE<br />

<strong>Command</strong><br />

History<br />

Related<br />

<strong>Command</strong>s<br />

Note: Layer 3 portion of guest VLAN and au<strong>the</strong>ntication fail VLANs can be created<br />

regardless if <strong>the</strong> VLAN is assigned to an interface or not. Once an interface is<br />

assigned a guest VLAN (which has an IP address), <strong>the</strong>n routing through <strong>the</strong> guest<br />

VLAN is <strong>the</strong> same as any o<strong>the</strong>r traffic. However, interface may join/leave a VLAN<br />

dynamically.<br />

dot1x auth-fail-vlan Configure a VLAN <strong>for</strong> au<strong>the</strong>ntication failures<br />

dot1x reau<strong>the</strong>ntication Enable periodic re-au<strong>the</strong>ntication<br />

show dot1x interface Display <strong>the</strong> 802.1x in<strong>for</strong>mation on an interface<br />

To return to <strong>the</strong> default, use <strong>the</strong> no dot1x max-eap-req command.<br />

number Enter <strong>the</strong> number of times an EAP request is transmitted be<strong>for</strong>e a session<br />

time-out.<br />

Range: 1 to 10<br />

Default: 2<br />

Version 7.6.1.0 Introduced on C-<strong>Series</strong> and S-<strong>Series</strong><br />

Version 7.4.1.0 Introduced on E-<strong>Series</strong><br />

interface range Configure a range of interfaces<br />

196 Security <strong>Command</strong>s

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!