9-18
Catalyst 2928 Switch Software Configuration Guide
OL-23389-01
Chapter 9 Configuring IEEE 802.1x Port-Based Authentication
Configuring IEEE 802.1x Authentication
Beginning with Cisco IOS Release 12.2(55)SE, you can filter out verbose system messages generated
by the authentication manager. The filtered content typically relates to authentication success. You can
also filter verbose messages for 802.1x authentication and MAB authentication. There is a separate
command for each authentication method:
•
The
no authentication logging verbose
global configuration command filters verbose messages
from the authentication manager.
•
The
no dot1x logging verbose
global configuration command filters 802.1x authentication verbose
messages.
•
The
no mab logging verbose
global configuration command filters MAC authentication bypass
(MAB) verbose messages
For more information, see the command reference for this release.
Number of seconds between
re-authentication attempts
3600 seconds.
Re-authentication number
2 times (number of times that the switch restarts the
authentication process before the port changes to the
unauthorized state).
Quiet period
60 seconds (number of seconds that the switch remains in
the quiet state following a failed authentication exchange
with the client).
Retransmission time
30 seconds (number of seconds that the switch should
wait for a response to an EAP request/identity frame
from the client before resending the request).
Maximum retransmission number
2 times (number of times that the switch will send an
EAP-request/identity frame before restarting the
authentication process).
Client timeout period
30 seconds (when relaying a request from the
authentication server to the client, the amount of time the
switch waits for a response before resending the request
to the client.)
Authentication server timeout period
30 seconds (when relaying a response from the client to
the authentication server, the amount of time the switch
waits for a reply before resending the response to the
server. This setting is not configurable.)
Guest VLAN
None specified.
Authenticator (switch) mode
None specified.
MAC authentication bypass
Disabled.
Table 9-2
Default IEEE 802.1x Authentication Configuration (continued)
Feature
Default Setting