Parameters
all
Enable all 802.1X debug messages.
auth-pae-fsm
Enable authentication PAE FSM debug messages.
backend-fsm
Enable backend FSM debug messages.
eapol-pdu
Enable the EAPOL frame trace and related debug messages.
interface
interface
Restricts the debugging information to an interface.
Defaults
Disabled
Command
Modes
EXEC Privilege
Command
History
Version 9.2(0.0)
Introduced on the MXL 10/40GbE Switch IO Module.
dot1x auth-fail-vlan
Configure an authentication failure VLAN for users and devices that fail 802.1X authentication.
Syntax
dot1x auth-fail-vlan
vlan-id
[max-attempts
number
]
To delete the authentication failure VLAN, use the
no dot1x auth-fail-vlan
vlan-id
[max-attempts
number
]
command.
Parameters
vlan-id
Enter the VLAN Identifier. The range is from 1 to 4094.
max-attempts
number
(OPTIONAL) Enter the keywords
max-attempts
followed
number of attempts desired before authentication fails. The
range is from 1 to 5. The default is
3
.
Defaults
3
attempts
Command
Modes
CONFIGURATION (
conf-if-interface-slot/port
)
Command
History
Version 9.2(0.0)
Introduced on the MXL 10/40GbE Switch IO Module.
Usage
Information
If the host responds to 802.1X with an incorrect login/password, the login fails. The
switch attempts to authenticate again until the maximum attempts configured is
reached. If the authentication fails after all allowed attempts, the interface moves
to the authentication failed VLAN.
After the authentication VLAN is assigned, the port-state must be toggled to restart
authentication. Authentication occurs at the next reauthentication interval (
dot1x
reauthentication
).
126
802.1X