<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic dot1x max-reauth-req in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/dot1x-max-reauth-req/m-p/5276588#M595723</link>
    <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As per Cisco Deployment Guidelines "&lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515" target="_blank" rel="noopener"&gt;ISE Secure Wired Access Prescriptive Deployment Guide&lt;/A&gt;"&amp;nbsp; , dot1x max-reauth-req 3 is defined on interface level. As per &lt;A href="https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_1-99/MAB/MAB_Dep_Guide.html#wp392315" target="_blank" rel="noopener"&gt;MAC Authentication Bypass Deployment Guide - Cisco&lt;/A&gt;, while configuring both MAB and dot1x on a interface , "s&lt;SPAN&gt;witch waits for a period of time defined by&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;dot1x timeout tx-period&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;and then sends another Request- Identity frame. The number of times it resends the Request-Identity frame is defined by&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;dot1x max-reauth-req&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The combination of tx-period and max-reauth-req is especially important to MAB endpoints in an IEEE 802.1X- enabled environment. MAB endpoints must wait until IEEE 802.1X times out before attempting network access through a fallback mechanism. The total time it takes for IEEE 802.1X to time out is determined by the following formula:&lt;/P&gt;&lt;P&gt;Timeout = (max-reauth-req +1) * tx-period&lt;/P&gt;&lt;P&gt;Question:&amp;nbsp; Is there any initial attempt by default,&amp;nbsp; so&amp;nbsp;(1 initial + 2 re-attempts). So the interface configuration should look like&amp;nbsp;dot1x max-reauth-req 2 instead of&amp;nbsp;dot1x max-reauth-req 3.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1048237" target="_blank" rel="noopener"&gt;@PSM&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/388087" target="_blank" rel="noopener"&gt;@Greg Gibbs&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036" target="_blank" rel="noopener"&gt;@Rob Ingram&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752" target="_blank" rel="noopener"&gt;@MHM Cisco World&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 31 Mar 2025 00:59:37 GMT</pubDate>
    <dc:creator>Mukesh-Kumar</dc:creator>
    <dc:date>2025-03-31T00:59:37Z</dc:date>
    <item>
      <title>dot1x max-reauth-req</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-max-reauth-req/m-p/5276588#M595723</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As per Cisco Deployment Guidelines "&lt;A href="https://community.cisco.com/t5/security-knowledge-base/ise-secure-wired-access-prescriptive-deployment-guide/ta-p/3641515" target="_blank" rel="noopener"&gt;ISE Secure Wired Access Prescriptive Deployment Guide&lt;/A&gt;"&amp;nbsp; , dot1x max-reauth-req 3 is defined on interface level. As per &lt;A href="https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_1-99/MAB/MAB_Dep_Guide.html#wp392315" target="_blank" rel="noopener"&gt;MAC Authentication Bypass Deployment Guide - Cisco&lt;/A&gt;, while configuring both MAB and dot1x on a interface , "s&lt;SPAN&gt;witch waits for a period of time defined by&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;dot1x timeout tx-period&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;and then sends another Request- Identity frame. The number of times it resends the Request-Identity frame is defined by&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;dot1x max-reauth-req&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The combination of tx-period and max-reauth-req is especially important to MAB endpoints in an IEEE 802.1X- enabled environment. MAB endpoints must wait until IEEE 802.1X times out before attempting network access through a fallback mechanism. The total time it takes for IEEE 802.1X to time out is determined by the following formula:&lt;/P&gt;&lt;P&gt;Timeout = (max-reauth-req +1) * tx-period&lt;/P&gt;&lt;P&gt;Question:&amp;nbsp; Is there any initial attempt by default,&amp;nbsp; so&amp;nbsp;(1 initial + 2 re-attempts). So the interface configuration should look like&amp;nbsp;dot1x max-reauth-req 2 instead of&amp;nbsp;dot1x max-reauth-req 3.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1048237" target="_blank" rel="noopener"&gt;@PSM&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/388087" target="_blank" rel="noopener"&gt;@Greg Gibbs&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036" target="_blank" rel="noopener"&gt;@Rob Ingram&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1065752" target="_blank" rel="noopener"&gt;@MHM Cisco World&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2025 00:59:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-max-reauth-req/m-p/5276588#M595723</guid>
      <dc:creator>Mukesh-Kumar</dc:creator>
      <dc:date>2025-03-31T00:59:37Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x max-reauth-req</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-max-reauth-req/m-p/5277005#M595746</link>
      <description>&lt;P&gt;What do you mean by "initial attempt by default" ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my lab I have this&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;rnolab-cml-v9k#show run int gi 1/0/1
Building configuration...

Current configuration : 392 bytes
!
interface GigabitEthernet1/0/1
 description PC1
 switchport access vlan 10
 switchport mode access
 device-tracking attach-policy IPDT_POLICY
 authentication periodic
 authentication timer reauthenticate server
 access-session port-control auto
 mab
 dot1x pae authenticator
 dot1x timeout tx-period 5
 spanning-tree portfast
 service-policy type control subscriber PORT-AUTH-POLICY-I
end
&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;rnolab-cml-v9k#show dot1x interface gigabitEthernet 1/0/1
Dot1x Info for GigabitEthernet1/0/1
--------------------------------------------
PAE                       = AUTHENTICATOR
QuietPeriod               = 60
ServerTimeout             = 0
SuppTimeout               = 30
ReAuthMax                 = 2
MaxReq                    = 2
TxPeriod                  = 5
&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 31 Mar 2025 23:39:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-max-reauth-req/m-p/5277005#M595746</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-03-31T23:39:20Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x max-reauth-req</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-max-reauth-req/m-p/5277176#M595756</link>
      <description>&lt;P&gt;Firstly, Thank you&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;for your feedback and time. Highly appreciate.&lt;/P&gt;&lt;P&gt;Here is configuration , I have, given below.&amp;nbsp; &amp;nbsp;Mab devices , in this case, I am particularly referring for Avaya Phone. Those phones, reboot, before IP being assigned. In our IBNS 2.0 Policy, dot1x is first preference, followed by MAB. Mab device (Avaya Phone) must wait until 802.1x times out before access network through MAB. As per Cisco documentation,&amp;nbsp;&lt;SPAN&gt;Cisco Catalyst switches have default values of tx-period&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;= 30 seconds and max-reauth-req&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;= 2.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Cisco documentation shows formula&amp;nbsp;Timeout = (max-reauth-req +1) * tx-period.&amp;nbsp; &amp;nbsp; I meant initial was to, if by default&amp;nbsp;max-reauth-req is 2 and as per Timeout formula 1 is being added to number of attempts (max-reauth-req).&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;My question is , if at interface level I should define&amp;nbsp;max-reauth-req to&amp;nbsp; 2 or 3.&amp;nbsp; &amp;nbsp;I am referring to formula in this documentation ( Figure 6&amp;nbsp;&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_1-99/MAB/MAB_Dep_Guide.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/solutions/Enterprise/Security/TrustSec_1-99/MAB/MAB_Dep_Guide.html&lt;/A&gt;).&amp;nbsp; If I look at formula 1 is being added to make dot1x attempts to 3.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I want to minimize the timeout period, so that Avaya phones get assigned IP, hence, thereafter, get authenticate using MAB.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ISETestSwitch-3#show dot1x interface gigabitEthernet 1/0/14&lt;BR /&gt;Dot1x Info for GigabitEthernet1/0/14&lt;BR /&gt;--------------------------------------------&lt;BR /&gt;PAE = AUTHENTICATOR&lt;BR /&gt;QuietPeriod = 60&lt;BR /&gt;ServerTimeout = 0&lt;BR /&gt;SuppTimeout = 30&lt;BR /&gt;ReAuthMax = 3&lt;BR /&gt;MaxReq = 2&lt;BR /&gt;TxPeriod = 7&lt;/P&gt;&lt;P&gt;ISETestSwitch-3#show running-config interface gigabitEthernet 1/0/14&lt;BR /&gt;Building configuration...&lt;/P&gt;&lt;P&gt;Current configuration : 691 bytes&lt;BR /&gt;!&lt;BR /&gt;interface GigabitEthernet1/0/14&lt;BR /&gt;description "Closed Mode"&lt;BR /&gt;switchport access vlan 288&lt;BR /&gt;switchport mode access&lt;BR /&gt;switchport voice vlan 3288&lt;BR /&gt;device-tracking attach-policy IPDT_POLICY&lt;BR /&gt;no cdp enable&lt;BR /&gt;authentication periodic&lt;BR /&gt;authentication timer reauthenticate server&lt;BR /&gt;authentication timer unauthorized 600&lt;BR /&gt;access-session control-direction in&lt;BR /&gt;access-session closed&lt;BR /&gt;access-session port-control auto&lt;BR /&gt;mab&lt;BR /&gt;dot1x pae authenticator&lt;BR /&gt;dot1x timeout tx-period 7&lt;BR /&gt;dot1x max-reauth-req 3&lt;BR /&gt;auto qos trust&lt;BR /&gt;spanning-tree portfast&lt;BR /&gt;service-policy type control subscriber DOT1X_MAB_POLICY&lt;BR /&gt;service-policy input AutoQos-4.0-Trust-Cos-Input-Policy&lt;BR /&gt;service-policy output AutoQos-4.0-Output-Policy&lt;/P&gt;</description>
      <pubDate>Tue, 01 Apr 2025 13:34:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-max-reauth-req/m-p/5277176#M595756</guid>
      <dc:creator>Mukesh-Kumar</dc:creator>
      <dc:date>2025-04-01T13:34:10Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x max-reauth-req</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-max-reauth-req/m-p/5277330#M595771</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1719386"&gt;@Mukesh-Kumar&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One important thing to remember, is that the dot1x timer only starts when the session starts, and not when the interface link goes up. It's very possible and also very common that if the switch interface link goes UP/UP, but there is no MAC address learned on the interface yet, then the session will not be created. As soon as the switch learns a MAC address, the session manager comes to life. In your case, with DOT1X 1st, the switch will now wait (3 + 1) * 7 seconds (28 seconds) for an EAPOL frame from the supplicant, or for a response to its own EAPOL frame request. I tested in the lab and it's exactly 28 seconds. So the formula is correct.&lt;/P&gt;
&lt;P&gt;You can play around with either of these two values&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;dot1x timeout tx-period 7&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;dot1x max-reauth-req 3&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;to come to the same result - if you want roughly 30 seconds, then those values are good. If you want less, then adjust either of them.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;if you make&amp;nbsp;max-reauth-req 2&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;then you have a wait of 21 seconds.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I was testing in my lab with ISE 3.4p1, a virtual C9000v switch (CML) and an ubuntu CML client. The ubuntu client has wpasupplicant on the Ethernet interface for testing purposes. But in this case I disabled the supplicant to force the timeout to occur. I also tested the supplicant authentication (I kept it simple with EAP-PEAP MSCHAPv2) and it worked flawlessly.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Apr 2025 00:07:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-max-reauth-req/m-p/5277330#M595771</guid>
      <dc:creator>Arne Bier</dc:creator>
      <dc:date>2025-04-02T00:07:10Z</dc:date>
    </item>
    <item>
      <title>Re: dot1x max-reauth-req</title>
      <link>https://community.cisco.com/t5/network-access-control/dot1x-max-reauth-req/m-p/5277895#M595812</link>
      <description>&lt;P&gt;Thank you very much for your time and support&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/158532"&gt;@Arne Bier&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 12:56:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/dot1x-max-reauth-req/m-p/5277895#M595812</guid>
      <dc:creator>Mukesh-Kumar</dc:creator>
      <dc:date>2025-04-03T12:56:47Z</dc:date>
    </item>
  </channel>
</rss>

