Client exclusion - Maximum 802.1 x-AAA failure attempts
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-05-2024 03:16 AM
Hello
Is it possible to change Maximum 802.1 x-AAA failure attempts values on WLC 9800 series?
The documentation only contains a description of this function, but does not indicate how to change this values
Excessive 802.1X Authentication Failures—Clients are excluded on the fourth 802.1X authentication attempt, after three consecutive failures.
For example by default Excessive 802.1X Authentication Failures is 3, can i change it to 5 or more ?
- Labels:
-
Catalyst Wireless Controllers
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-05-2024 04:22 AM
- Using some kind of 'brute force attack' on the issue with :
# show running-config all | inc aaa
I notice :
>....
>aaa authentication attempts login 3
>...
Change accordingly (with CLI in the running-config) , check if that works as intended
M.
-- Each morning when I wake up and look into the mirror I always say ' Why am I so brilliant ? '
When the mirror will then always repond to me with ' The only thing that exceeds your brilliance is your beauty! '
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-07-2024 06:42 AM
thanks, I'll try this option

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-06-2024 07:44 AM
AFAIK client exclusion is handled at the authentication server
if this is Active Directory -> check there
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-07-2024 04:53 AM
The wlc exclusive list have it policy and this policy have defualt set for times authc failed are this what you ask for?
MHM
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
02-07-2024 06:40 AM
Yes. Is it possible to change the values in this policy so that the client gets on the exclusive list, for example, after 5 attempts ?
