Configuring 802.1X Authentication set dot1x auth-config
25-8 Authentication Configuration
Parameters
Defaults
If port‐stringisnotspecified,authenticationparameterswillbesetonallports
Mode
Switchcommand,Read‐Write.
Examples
ThisexampleshowshowtosetEAPOLportcontroltoforcedauthorizedmodeonportsfe.1.1‐5,
whichdisablesauthenticationontheseports:
Matrix(rw)->set dot1x auth-config authcontrolled-portcontrol forced-auth fe.1.1-5
authcontrolled‐
portcontrolauto|
forced‐auth|forced‐
unauth
SpecifiestheEAPOLportcontrolmodeas:
• auto‐Autoauthorizationmode(default).TheEnterasysMatrix
systemwillonlyforwardframesreceivedonaportwhichare
consideredauthenticatedaccordingtothestateofthe
correspondingaccessentity.
• forced‐auth‐Forcedauthorized
mode,whicheffectivelydisables
802.1Xauthenticationontheport,andallowsallframesreceivedon
theporttobeforwarded.
• forced‐unauth‐Forcedunauthorizedmode,whicheffectively
disables802.1Xauthenticationontheport.When802.1Xistheonly
activeauthenticationagentonagivenport,thissettingmeansall
framesreceivedwillbedropped.
keytxenabledfalse|
true
Enables(true)ordisables( false)802.1Xkeytransmissionbythe
authenticatorPAEstatemachine.
maxreqvalue Specifiesthemaximumnumberofauthenticationrequestsallowedby
thebackendauthenticationstatemachine.Validvaluesare1‐10.
quietperiodvalue Specifiesthetime(inseconds)
followingafailedauthenticationbefore
anotherattemptcanbemadebytheauthenticatorPAEstatemachine.
Validvaluesare0‐65535.
reauthenabledfalse|
true
Enables(true)ordisables( false)reauthenticationcontrolofthe
reauthenticationtimerstatemachine.
reauthperiodvalue Specifiesthetimelapse(inseconds)betweenattemptsbythe
reauthenticationtimerstatemachinetoreauthenticateaport.Valid
valuesare0‐65535.
servertimeouttimeout Specifiesatimeoutperiod(inseconds)fortheauthenticationserver,
usedbythebackendauthenticationstatemachine.Validvaluesare1‐
300.
supptimeouttimeout Specifiesatimeoutperiod(inseconds)forthe authenticationsupplicant
usedby
thebackendauthenticationstatemachine.Validvaluesare1‐
300.
txperiodvalue Specifiestheperiod(inseconds)whichpassesbetweenauthenticator
PAEstatemachineEAPtransmissions.Validvaluesare1‐65535.
port‐string (Optional)Limitstheconfigurationofdesiredsettingstospecified
port(s).Foradetaileddescriptionofpossibleport‐string
values,referto
“PortStringSyntaxUsedintheCLI”onpage 4‐2.