<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: dot1x re-authenticate &amp; dot1x initialize in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dot1x-re-authenticate-dot1x-initialize/m-p/572132#M426695</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is a debug on dot1x re-authenticate;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C2960#sh dot1x int g0/11 d&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dot1x Info for GigabitEthernet0/11&lt;/P&gt;&lt;P&gt;-----------------------------------&lt;/P&gt;&lt;P&gt;PAE                       = AUTHENTICATOR&lt;/P&gt;&lt;P&gt;PortControl               = AUTO&lt;/P&gt;&lt;P&gt;ControlDirection          = Both&lt;/P&gt;&lt;P&gt;HostMode                  = SINGLE_HOST&lt;/P&gt;&lt;P&gt;ReAuthentication          = Disabled&lt;/P&gt;&lt;P&gt;QuietPeriod               = 60&lt;/P&gt;&lt;P&gt;ServerTimeout             = 30&lt;/P&gt;&lt;P&gt;SuppTimeout               = 30&lt;/P&gt;&lt;P&gt;ReAuthPeriod              = 3600 (Locally configured)&lt;/P&gt;&lt;P&gt;ReAuthMax                 = 1&lt;/P&gt;&lt;P&gt;MaxReq                    = 2&lt;/P&gt;&lt;P&gt;TxPeriod                  = 1&lt;/P&gt;&lt;P&gt;RateLimitPeriod           = 0&lt;/P&gt;&lt;P&gt;Mac-Auth-Bypass           = Enabled&lt;/P&gt;&lt;P&gt;Critical-Auth             = Enabled&lt;/P&gt;&lt;P&gt;Critical Recovery Action  = Reinitialize&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dot1x Authenticator Client List&lt;/P&gt;&lt;P&gt;-------------------------------&lt;/P&gt;&lt;P&gt;Supplicant                = 0000.3926.0384&lt;/P&gt;&lt;P&gt;        Auth SM State     = AUTHENTICATED&lt;/P&gt;&lt;P&gt;        Auth BEND SM Stat = IDLE&lt;/P&gt;&lt;P&gt;Port Status               = AUTHORIZED&lt;/P&gt;&lt;P&gt;Authentication Method     = MAB&lt;/P&gt;&lt;P&gt;Authorized By             = Authentication Server&lt;/P&gt;&lt;P&gt;Vlan Policy               = N/A&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C2960#dot1x re&lt;/P&gt;&lt;P&gt;C2960#dot1x re-authenticate int g0/11&lt;/P&gt;&lt;P&gt;C2960#&lt;/P&gt;&lt;P&gt;Aug  8 00:47:42: dot1x-ev:dot1x_exec_reauth_interface: Reauthenticating Authenticator instances on GigabitEthernet0/11&lt;/P&gt;&lt;P&gt;Aug  8 00:47:42: dot1x-ev:Sending create new context event to EAP for 0000.3926.0384&lt;/P&gt;&lt;P&gt;Aug  8 00:47:43: dot1x-ev:Received an EAP Fail on GigabitEthernet0/11 for mac 0000.3926.0384&lt;/P&gt;&lt;P&gt;Aug  8 00:47:43: dot1x-ev:No reply attributes received from AAA for 0000.3926.0384&lt;/P&gt;&lt;P&gt;Aug  8 00:47:43: dot1x-ev:dot1x_critical_authc_fail: Critical Auth enabled, retaining existing authorization on port GigabitEthernet0/11&lt;/P&gt;&lt;P&gt;Aug  8 00:47:43: dot1x-ev:dot1x_switch_addr_add: Host access entry already exists for 0000.3926.0384 101&lt;/P&gt;&lt;P&gt;Aug  8 00:47:43: dot1x-ev:dot1x_switch_addr_add: Added MAC 0000.3926.0384 to vlan 101 on interface GigabitEthernet0/11&lt;/P&gt;&lt;P&gt;Aug  8 00:47:43: dot1x-ev:Received successful Authz complete for 0000.3926.0384&lt;/P&gt;&lt;P&gt;Aug  8 00:47:43: dot1x-ev:GigabitEthernet0/11:Sending EAPOL packet to group PAE address&lt;/P&gt;&lt;P&gt;Aug  8 00:47:43: dot1x-ev:dot1x_mgr_pre_process_eapol_pak: Role determination not required on GigabitEthernet0/11.&lt;/P&gt;&lt;P&gt;Aug  8 00:47:43: dot1x-ev:dot1x_mgr_send_eapol: Sending out EAPOL packet on GigabitEthernet0/11&lt;/P&gt;&lt;P&gt;C2960#&lt;/P&gt;&lt;P&gt;C2960#sh dot1x int g0/11 d&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dot1x Info for GigabitEthernet0/11&lt;/P&gt;&lt;P&gt;-----------------------------------&lt;/P&gt;&lt;P&gt;PAE                       = AUTHENTICATOR&lt;/P&gt;&lt;P&gt;PortControl               = AUTO&lt;/P&gt;&lt;P&gt;ControlDirection          = Both&lt;/P&gt;&lt;P&gt;HostMode                  = SINGLE_HOST&lt;/P&gt;&lt;P&gt;ReAuthentication          = Disabled&lt;/P&gt;&lt;P&gt;QuietPeriod               = 60&lt;/P&gt;&lt;P&gt;ServerTimeout             = 30&lt;/P&gt;&lt;P&gt;SuppTimeout               = 30&lt;/P&gt;&lt;P&gt;ReAuthPeriod              = 3600 (Locally configured)&lt;/P&gt;&lt;P&gt;ReAuthMax                 = 1&lt;/P&gt;&lt;P&gt;MaxReq                    = 2&lt;/P&gt;&lt;P&gt;TxPeriod                  = 1&lt;/P&gt;&lt;P&gt;RateLimitPeriod           = 0&lt;/P&gt;&lt;P&gt;Mac-Auth-Bypass           = Enabled&lt;/P&gt;&lt;P&gt;Critical-Auth             = Enabled&lt;/P&gt;&lt;P&gt;Critical Recovery Action  = Reinitialize&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dot1x Authenticator Client List&lt;/P&gt;&lt;P&gt;-------------------------------&lt;/P&gt;&lt;P&gt;Supplicant                = 0000.3926.0384&lt;/P&gt;&lt;P&gt;        Auth SM State     = AUTHENTICATED&lt;/P&gt;&lt;P&gt;        Auth BEND SM Stat = IDLE&lt;/P&gt;&lt;P&gt;Port Status               = AUTHORIZED&lt;/P&gt;&lt;P&gt;Authentication Method     = MAB&lt;/P&gt;&lt;P&gt;Authorized By             = Authentication Server&lt;/P&gt;&lt;P&gt;Vlan Policy               = N/A&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C2960#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 09 Aug 2006 03:37:20 GMT</pubDate>
    <dc:creator />
    <dc:date>2006-08-09T03:37:20Z</dc:date>
    <item>
      <title>dot1x re-authenticate &amp; dot1x initialize</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-re-authenticate-dot1x-initialize/m-p/572131#M426692</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im trying dot1x with critical authentication plus MAC authentication bypass,&lt;/P&gt;&lt;P&gt;on Cat2960 with SEE2.&lt;/P&gt;&lt;P&gt;Its onfigration is the following;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;aaa new-model&lt;/P&gt;&lt;P&gt;aaa authentication login cisco local&lt;/P&gt;&lt;P&gt;aaa authentication dot1x default group radius&lt;/P&gt;&lt;P&gt;aaa authorization network default group radius&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;dot1x system-auth-control&lt;/P&gt;&lt;P&gt;dot1x critical eapol&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;interface GigabitEthernet0/11&lt;/P&gt;&lt;P&gt; switchport access vlan 101&lt;/P&gt;&lt;P&gt; switchport mode access&lt;/P&gt;&lt;P&gt; dot1x mac-auth-bypass&lt;/P&gt;&lt;P&gt; dot1x critical&lt;/P&gt;&lt;P&gt; dot1x critical recovery action reinitialize&lt;/P&gt;&lt;P&gt; dot1x pae authenticator&lt;/P&gt;&lt;P&gt; dot1x port-control auto&lt;/P&gt;&lt;P&gt; dot1x timeout tx-period 1&lt;/P&gt;&lt;P&gt; dot1x max-reauth-req 1&lt;/P&gt;&lt;P&gt; spanning-tree portfast&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;radius-server dead-criteria time 5&lt;/P&gt;&lt;P&gt;radius-server attribute 32 include-in-access-req format %h&lt;/P&gt;&lt;P&gt;no radius-server attribute nas-port&lt;/P&gt;&lt;P&gt;radius-server host 10.1.1.1 auth-port 1812 acct-port 1813 test username TEST idle-time 1&lt;/P&gt;&lt;P&gt;radius-server source-ports 1645-1646&lt;/P&gt;&lt;P&gt;radius-server key Cisco(%$%&lt;/P&gt;&lt;P&gt;radius-server vsa send accounting&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When RADIUS server is down after a client is authenticated and the 2 commands,&lt;/P&gt;&lt;P&gt;dot1x re-authenticate int and dot1x initialize int are issued,&lt;/P&gt;&lt;P&gt;it does not change to critical auth state, remaining authorized by server with&lt;/P&gt;&lt;P&gt; dot1x re-authenticate command.&lt;/P&gt;&lt;P&gt;This result is correct?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CCO says,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Using IEEE 802.1x Authentication with Inaccessible Authentication Bypass&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/univercd/cc/td/doc/product/lan/cat2960/12225see/scg/sw8021x.htm#wp1194433" target="_blank"&gt;http://www.cisco.com/univercd/cc/td/doc/product/lan/cat2960/12225see/scg/sw8021x.htm#wp1194433&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the port is already authorized and re-authentication occurs, the switch puts &lt;/P&gt;&lt;P&gt;the critical port in the critical-authentication state in the current VLAN, &lt;/P&gt;&lt;P&gt;which might be the one previously assigned by the RADIUS server. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please give me any help.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:42:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-re-authenticate-dot1x-initialize/m-p/572131#M426692</guid>
      <dc:creator>admin_2</dc:creator>
      <dc:date>2019-03-10T21:42:05Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x re-authenticate &amp; dot1x initialize</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-re-authenticate-dot1x-initialize/m-p/572132#M426695</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here is a debug on dot1x re-authenticate;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C2960#sh dot1x int g0/11 d&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dot1x Info for GigabitEthernet0/11&lt;/P&gt;&lt;P&gt;-----------------------------------&lt;/P&gt;&lt;P&gt;PAE                       = AUTHENTICATOR&lt;/P&gt;&lt;P&gt;PortControl               = AUTO&lt;/P&gt;&lt;P&gt;ControlDirection          = Both&lt;/P&gt;&lt;P&gt;HostMode                  = SINGLE_HOST&lt;/P&gt;&lt;P&gt;ReAuthentication          = Disabled&lt;/P&gt;&lt;P&gt;QuietPeriod               = 60&lt;/P&gt;&lt;P&gt;ServerTimeout             = 30&lt;/P&gt;&lt;P&gt;SuppTimeout               = 30&lt;/P&gt;&lt;P&gt;ReAuthPeriod              = 3600 (Locally configured)&lt;/P&gt;&lt;P&gt;ReAuthMax                 = 1&lt;/P&gt;&lt;P&gt;MaxReq                    = 2&lt;/P&gt;&lt;P&gt;TxPeriod                  = 1&lt;/P&gt;&lt;P&gt;RateLimitPeriod           = 0&lt;/P&gt;&lt;P&gt;Mac-Auth-Bypass           = Enabled&lt;/P&gt;&lt;P&gt;Critical-Auth             = Enabled&lt;/P&gt;&lt;P&gt;Critical Recovery Action  = Reinitialize&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dot1x Authenticator Client List&lt;/P&gt;&lt;P&gt;-------------------------------&lt;/P&gt;&lt;P&gt;Supplicant                = 0000.3926.0384&lt;/P&gt;&lt;P&gt;        Auth SM State     = AUTHENTICATED&lt;/P&gt;&lt;P&gt;        Auth BEND SM Stat = IDLE&lt;/P&gt;&lt;P&gt;Port Status               = AUTHORIZED&lt;/P&gt;&lt;P&gt;Authentication Method     = MAB&lt;/P&gt;&lt;P&gt;Authorized By             = Authentication Server&lt;/P&gt;&lt;P&gt;Vlan Policy               = N/A&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C2960#dot1x re&lt;/P&gt;&lt;P&gt;C2960#dot1x re-authenticate int g0/11&lt;/P&gt;&lt;P&gt;C2960#&lt;/P&gt;&lt;P&gt;Aug  8 00:47:42: dot1x-ev:dot1x_exec_reauth_interface: Reauthenticating Authenticator instances on GigabitEthernet0/11&lt;/P&gt;&lt;P&gt;Aug  8 00:47:42: dot1x-ev:Sending create new context event to EAP for 0000.3926.0384&lt;/P&gt;&lt;P&gt;Aug  8 00:47:43: dot1x-ev:Received an EAP Fail on GigabitEthernet0/11 for mac 0000.3926.0384&lt;/P&gt;&lt;P&gt;Aug  8 00:47:43: dot1x-ev:No reply attributes received from AAA for 0000.3926.0384&lt;/P&gt;&lt;P&gt;Aug  8 00:47:43: dot1x-ev:dot1x_critical_authc_fail: Critical Auth enabled, retaining existing authorization on port GigabitEthernet0/11&lt;/P&gt;&lt;P&gt;Aug  8 00:47:43: dot1x-ev:dot1x_switch_addr_add: Host access entry already exists for 0000.3926.0384 101&lt;/P&gt;&lt;P&gt;Aug  8 00:47:43: dot1x-ev:dot1x_switch_addr_add: Added MAC 0000.3926.0384 to vlan 101 on interface GigabitEthernet0/11&lt;/P&gt;&lt;P&gt;Aug  8 00:47:43: dot1x-ev:Received successful Authz complete for 0000.3926.0384&lt;/P&gt;&lt;P&gt;Aug  8 00:47:43: dot1x-ev:GigabitEthernet0/11:Sending EAPOL packet to group PAE address&lt;/P&gt;&lt;P&gt;Aug  8 00:47:43: dot1x-ev:dot1x_mgr_pre_process_eapol_pak: Role determination not required on GigabitEthernet0/11.&lt;/P&gt;&lt;P&gt;Aug  8 00:47:43: dot1x-ev:dot1x_mgr_send_eapol: Sending out EAPOL packet on GigabitEthernet0/11&lt;/P&gt;&lt;P&gt;C2960#&lt;/P&gt;&lt;P&gt;C2960#sh dot1x int g0/11 d&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dot1x Info for GigabitEthernet0/11&lt;/P&gt;&lt;P&gt;-----------------------------------&lt;/P&gt;&lt;P&gt;PAE                       = AUTHENTICATOR&lt;/P&gt;&lt;P&gt;PortControl               = AUTO&lt;/P&gt;&lt;P&gt;ControlDirection          = Both&lt;/P&gt;&lt;P&gt;HostMode                  = SINGLE_HOST&lt;/P&gt;&lt;P&gt;ReAuthentication          = Disabled&lt;/P&gt;&lt;P&gt;QuietPeriod               = 60&lt;/P&gt;&lt;P&gt;ServerTimeout             = 30&lt;/P&gt;&lt;P&gt;SuppTimeout               = 30&lt;/P&gt;&lt;P&gt;ReAuthPeriod              = 3600 (Locally configured)&lt;/P&gt;&lt;P&gt;ReAuthMax                 = 1&lt;/P&gt;&lt;P&gt;MaxReq                    = 2&lt;/P&gt;&lt;P&gt;TxPeriod                  = 1&lt;/P&gt;&lt;P&gt;RateLimitPeriod           = 0&lt;/P&gt;&lt;P&gt;Mac-Auth-Bypass           = Enabled&lt;/P&gt;&lt;P&gt;Critical-Auth             = Enabled&lt;/P&gt;&lt;P&gt;Critical Recovery Action  = Reinitialize&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dot1x Authenticator Client List&lt;/P&gt;&lt;P&gt;-------------------------------&lt;/P&gt;&lt;P&gt;Supplicant                = 0000.3926.0384&lt;/P&gt;&lt;P&gt;        Auth SM State     = AUTHENTICATED&lt;/P&gt;&lt;P&gt;        Auth BEND SM Stat = IDLE&lt;/P&gt;&lt;P&gt;Port Status               = AUTHORIZED&lt;/P&gt;&lt;P&gt;Authentication Method     = MAB&lt;/P&gt;&lt;P&gt;Authorized By             = Authentication Server&lt;/P&gt;&lt;P&gt;Vlan Policy               = N/A&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C2960#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Aug 2006 03:37:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-re-authenticate-dot1x-initialize/m-p/572132#M426695</guid>
      <dc:creator />
      <dc:date>2006-08-09T03:37:20Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x re-authenticate &amp; dot1x initialize</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-re-authenticate-dot1x-initialize/m-p/572133#M426696</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Debug on dot1x initialize;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C2960#dot1x initialize int g0/11&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Aug  8 00:50:00: dot1x-ev:dot1x_exec_init_interface: Initializing Authenticator instances on GigabitEthernet0/11&lt;/P&gt;&lt;P&gt;Aug  8 00:50:00: dot1x-ev:dot1x_switch_port_unauthorized: Unauthorizing interface GigabitEthernet0/11&lt;/P&gt;&lt;P&gt;Aug  8 00:50:00: dot1x-ev:dot1x_switch_is_dot1x_forwarding_enabled: Forwarding is disabled on Gi0/11&lt;/P&gt;&lt;P&gt;Aug  8 00:50:00: dot1x-ev:vlan 101 vp is removed on the interface GigabitEthernet0/11&lt;/P&gt;&lt;P&gt;Aug  8 00:50:00: dot1x-ev:dot1x_switch_addr_remove: Removed MAC 0000.3926.0384 from vlan 101 on interface GigabitEthernet0/11&lt;/P&gt;&lt;P&gt;Aug  8 00:50:00: dot1x-ev:dot1x_vlan_assign_client_deleted on interface GigabitEthernet0/11&lt;/P&gt;&lt;P&gt;Aug  8 00:50:00: dot1x-ev:Sending create new context event to EAP for 0000.0000.0000&lt;/P&gt;&lt;P&gt;Aug  8 00:50:00: dot1x-ev:Created a client entry for the supplicant 0000.0000.0000&lt;/P&gt;&lt;P&gt;Aug  8 00:50:00: dot1x-ev:Created a default authenticator instance on GigabitEthernet0/11&lt;/P&gt;&lt;P&gt;Aug  8 00:50:01: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/11, changed state to down&lt;/P&gt;&lt;P&gt;Aug  8 00:50:01: dot1x-ev:Received an EAP Fail on GigabitEthernet0/11 for mac 0000.0000.0000&lt;/P&gt;&lt;P&gt;Aug  8 00:50:01: dot1x-ev:No reply attributes received from AAA for 0000.0000.0000&lt;/P&gt;&lt;P&gt;Aug  8 00:50:01: dot1x-ev:dot1x_critical_authc_fail: Critical Auth enabled, authenticating port GigabitEthernet0/11&lt;/P&gt;&lt;P&gt;Aug  8 00:50:01: dot1x-ev:dot1x_switch_critical_vlan_policy: No Critical Auth VLAN defined for&lt;/P&gt;&lt;P&gt;port GigabitEthernet0/11&lt;/P&gt;&lt;P&gt;Aug  8 00:50:01: dot1x-ev:Updating feature config&lt;/P&gt;&lt;P&gt;Aug  8 00:50:01: dot1x-ev:dot1x_critical_modify_host_mode: Critical Auth feature overriding host_mode on port GigabitEthernet0/11, forcing to DOT1X_MULTI_HOST&lt;/P&gt;&lt;P&gt;Aug  8 00:50:01: dot1x-ev:dot1x_switch_is_dot1x_forwarding_enabled: Forwarding is disabled on Gi0/11&lt;/P&gt;&lt;P&gt;Aug  8 00:50:01: dot1x-ev:vlan 101 vp is added on the interface GigabitEthernet0/11&lt;/P&gt;&lt;P&gt;Aug  8 00:50:01: dot1x-ev:dot1x_switch_is_dot1x_forwarding_enabled: Forwarding is disabled on Gi0/11&lt;/P&gt;&lt;P&gt;Aug  8 00:50:01: dot1x-ev:dot1x_critical_modify_host_mode: Critical Auth feature overriding host_mode on port GigabitEthernet0/11, forcing to DOT1X_MULTI_HOST&lt;/P&gt;&lt;P&gt;Aug  8 00:50:01: dot1x-ev:dot1x_critical_modify_host_mode: Critical Auth feature overriding host_mode on port GigabitEthernet0/11, forcing to DOT1X_MULTI_HOST&lt;/P&gt;&lt;P&gt;Aug  8 00:50:01: dot1x-ev:dot1x_switch_port_authorized: set dot1x ask handler on interface GigabitEthernet0/11&lt;/P&gt;&lt;P&gt;Aug  8 00:50:01: dot1x-ev:Received successful Authz complete for 0000.0000.0000&lt;/P&gt;&lt;P&gt;Aug  8 00:50:01: dot1x-ev:GigabitEthernet0/11:Sending EAPOL packet to group PAE address&lt;/P&gt;&lt;P&gt;Aug  8 00:50:01: dot1x-ev:dot1x_mgr_pre_process_eapol_pak: Role determination not required on GigabitEthernet0/11.&lt;/P&gt;&lt;P&gt;Aug  8 00:50:01: dot1x-ev:dot1x_mgr_send_eapol: Sending out EAPOL packet on GigabitEthernet0/11&lt;/P&gt;&lt;P&gt;Aug  8 00:50:02: %LINEPROTO-5-UPDOWN: Line protocol on Interface GigabitEthernet0/11, changed state to up&lt;/P&gt;&lt;P&gt;C2960#&lt;/P&gt;&lt;P&gt;C2960#&lt;/P&gt;&lt;P&gt;C2960#sh dot1x int g0/11 d&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dot1x Info for GigabitEthernet0/11&lt;/P&gt;&lt;P&gt;-----------------------------------&lt;/P&gt;&lt;P&gt;PAE                       = AUTHENTICATOR&lt;/P&gt;&lt;P&gt;PortControl               = AUTO&lt;/P&gt;&lt;P&gt;ControlDirection          = Both&lt;/P&gt;&lt;P&gt;HostMode                  = SINGLE_HOST&lt;/P&gt;&lt;P&gt;ReAuthentication          = Disabled&lt;/P&gt;&lt;P&gt;QuietPeriod               = 60&lt;/P&gt;&lt;P&gt;ServerTimeout             = 30&lt;/P&gt;&lt;P&gt;SuppTimeout               = 30&lt;/P&gt;&lt;P&gt;ReAuthPeriod              = 3600 (Locally configured)&lt;/P&gt;&lt;P&gt;ReAuthMax                 = 1&lt;/P&gt;&lt;P&gt;MaxReq                    = 2&lt;/P&gt;&lt;P&gt;TxPeriod                  = 1&lt;/P&gt;&lt;P&gt;RateLimitPeriod           = 0&lt;/P&gt;&lt;P&gt;Mac-Auth-Bypass           = Enabled&lt;/P&gt;&lt;P&gt;Critical-Auth             = Enabled&lt;/P&gt;&lt;P&gt;Critical Recovery Action  = Reinitialize&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Dot1x Authenticator Client List Empty&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Port Status               = AUTHORIZED&lt;/P&gt;&lt;P&gt;Authorized By             = Critical-Auth&lt;/P&gt;&lt;P&gt;Operational HostMode      = MULTI_HOST&lt;/P&gt;&lt;P&gt;Vlan Policy               = N/A&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;C2960#&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 09 Aug 2006 03:42:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-re-authenticate-dot1x-initialize/m-p/572133#M426696</guid>
      <dc:creator />
      <dc:date>2006-08-09T03:42:17Z</dc:date>
    </item>
  </channel>
</rss>

