Specifications

Managing 802.1X Client Reauthentication
19-6 Managing 802.1X on the RoamAbout Switch
Setting the Maximum Number of 802.1X Reauthentication Attempts
Thefollowingcommandsetsthenumberofreauthenticationattempt sthattheRASmakesbefore
thesupplicant(client)becomesunauthorized:
set dot1x reauth-max number-of-attempts
Thedefaultnumberofreauthenticationattemptsis2.Youcanspecifyfrom1to10attempts.
Examples
Typethefollowingcommandtosetthenumberofauthenticationattemptsto8:
RBT-8100# set dot1x reauth-max 8
success: dot1x max reauth set to 8.
Typethefollowingcommandtoresetthemaximumnumberofreauthorizationattemptstothe
default:
RBT-8100# clear dot1x reauth-max
success: change accepted.
Setting the 802.1X Reauthentication Period
ThefollowingcommandconfiguresthenumberofsecondsthattheRASwaitsbeforeattempt ing
reauthentication:
set dot1x reauth-period seconds
Thedefaultis3600 seconds(1 hour).Therangeisfrom60 to1 ,64 1,600 seconds (19 days).This
valuecanbeoverriddenbyuserauthorizationparameters.
MSSreauthenticatesdynamicWEPclientsbasedonthereauthenticationtimer.MSSalso
reauthenticatesWPAclientsiftheclientsusetheWEP40orWEP104cipher.Foreachdynamic
WEP
clientorWPAclientusingaWEPcipher,thereauthenticationtimerissettothelesserofthe
globalsettingorthevaluereturnedbytheAAAserverwith therestoftheauthorizationattributes
forthatclient.
Examples
Typethefollowingcommandtosetthenumberofsecondsto100beforereauthenticationis
attempted:
RBT-8100# set dot1x reauth-period 100
success: dot1x auth-server timeout set to 100.
Note: If the number of reauthentications for a wired authentication client is greater than the
maximum number of reauthentications allowed, MSS sends an EAP failure packet to the client and
removes the client from the network. However, MSS does not remove a wireless client from the
network under these circumstances.