03-21-2011 07:34 AM - edited 03-10-2019 05:55 PM
Hi,
a customer has configured an dot1x scenario in a lab envoirenment to test setup before rollout. he configured dot1x multi-auth with open mode (because there are a lot of clients that can not authenticate at this time), radius and mab. now he has the problem, that the switch every minute tries to reauthenticate unathorized clients and never stops, these causes a lot of unwanted requests on the acs server. we already tried a lot of settings and timeouts, but nothing worked. is there any way to configure the switch to retries only 3 times with a wait time of 5 minute between every retry? we also tried configure authentication fallback, but this doesn't work with multi-auth.
regards,
Roberto
03-24-2011 01:03 AM
Hi Roberto,
Can you share with us the switch port configuration? Maybe you have re-authentication configured and this would expalin why the switch attempts every minute.
If you do not want re-authentication to happen: "no dot1x reauthentication" or in later versions "no authentication periodic".
Regarding tweaking the timers wih the goal of configure the switch to retry only 3 times with a wait time of 5 minute between every retry:
These commands are available in the dot1x config guides, like:
HTH,
Tiago
--
If this helps you and/or answers your question please mark the question as "answered" and/or rate it, so other users can easily find it.
03-29-2011 06:53 AM
Hi Tiago,
I want an periodic re-authentication, but only for "authorized" clients, this has been set to 1 hour.
I already tried to set dot1x max-reauth-req and dot1x timeout tx-period and this worked well as they should (and expected). The Switch sent EAPPOL three times (the first one and the two from max-reauth-req) with a wait time of 10 seconds and the client has been showed as unauthorized. But after 60 seconds the switch begins the authentication process again, and that is what I don't want. Maybe there are undocumented configuration settings to disable this behavior.
regards,
Roberto
03-30-2011 04:01 AM
Hi Tiago,
i also set the dot1x timeout quiet-period to an other value than 60 seconds (default), but the described behavior did not not change.
regards,
Roberto
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide