C
HAPTER
23
| Authentication Commands
802.1X Port Authentication
– 848 –
COMMAND USAGE
This command sets the timeout for EAP-request frames other than EAP-
request/identity frames. If dot1x authentication is enabled on a port, the
switch will initiate authentication when the port link state comes up. It will
send an EAP-request/identity frame to the client to request its identity,
followed by one or more requests for authentication information. It may
also send other EAP-request frames to the client during an active
connection as required for reauthentication.
EXAMPLE
Console(config)#interface eth 1/2
Console(config-if)#dot1x timeout supp-timeout 300
Console(config-if)#
dot1x timeout
tx-period
This command sets the time that an interface on the switch waits during an
authentication session before re-transmitting an EAP packet. Use the no
form to reset to the default value.
SYNTAX
dot1x timeout tx-period seconds
no dot1x timeout tx-period
seconds - The number of seconds. (Range: 1-65535)
DEFAULT
30 seconds
COMMAND MODE
Interface Configuration
EXAMPLE
Console(config)#interface eth 1/2
Console(config-if)#dot1x timeout tx-period 300
Console(config-if)#
dot1x
re-authenticate
This command forces re-authentication on all ports or a specific interface.
SYNTAX
dot1x re-authenticate [interface]
interface
ethernet unit/port
unit - Unit identifier. (Range: 1)
port - Port number. (Range: 1-28/52)