Hi,
We have done some testing with 802.1x on IOS 12.1(13)EA1c on Cisco 3550 switches.
If the switch does not get an answer from a radius server, then it will retry after some period.
There seems to be a timer in the switch that has some influence on this behaviour.
This timer can not be changed in this IOS version. It can be seen with the debug dot1x core command.
Output: dot1x-core(Fa0/1): timer A_WHILE expired
This A_WHILE timer expires every 30 seconds if there is no answer from the RADIUS servers.
The switch will abort the first EAP conversation with the supplicant and start a second EAP conversation with
an EAP request identity. The port will not become HELD.
Does anyone know why this timer exists ?
And can it be modified ?
Regards, Gerard van Bon