MES53xx, MES33xx, MES23xx Ethernet Switch Series
154
Table 5.166. Ethernet interface configuration mode commands
Command
Value/Default value
Action
dot1x port-control {auto |
force-authorized |
forceunauthorized-
*timerange
time
]
-/force-authorized
time: (1..32)
Configure 802.1X authentication on the interface. Enable
manual monitoring of the port authorization state.
-
auto
- use 802.1X to change client state from authorized to
unauthorized and visa versa
-
force-authorized
- disable 802.1X authentication on the
interface. The port will switch to the authorized state without
authentication.
-
force-unauthorized
- changes the port state to unauthorized
.
All client authentication attempts are ignored, the switch will
not provide the authentication service for this port.
-
time
- time interval. If this parameter is not specified, the
port will not be authorized.
no dot1x port-control
Set the default value.
dot1x reauthentication
-/repeated authentication
checks are disabled
Enable
repeated
client
authentication
checks
(re-
authentication).
no dot1x reauthentication
Disable
repeated
client
authentication
checks
(re-
authentication).
dot1x timeout
reauthperiod
period
period:
(300..4294967295)/3600
seconds
Specify the period between repeated authentication checks.
no dot1x timeout
reauthperiod
Set the default value.
dot1x timeout quiet-period
period
period: (10..65535)/60
seconds
Specify the period during which the switch will remain in the
silent state after an unsuccessful authentication attempt.
During this period, the switch will not accept nor initiate any
authentication messages.
no dot1x timeout
quietperiod
Set the default value.
dot1x timeout tx-period
period
period: (30..65535)/30
seconds
Specify the period during which the switch will wait for the
response to the request or EAP identification from the client
before re-sending the request.
no dot1x timeout tx-period
Set the default value.
dot1x max-req
count
count: (1..10)/2
Specify the maximum number of attempts for sending request
to the EAP client before initiating new authentication process.
no dot1x max-req
Set the default value.
dot1x timeout
supptimeout
period
period: (1..65535)/30
seconds
Specify the period between repeated requests to the EAP
client.
no dot1x timeout
supptimeout
Set the default value.
dot1x timeout
servertimeout
period
period: (1..65535)/30
seconds
Specify a period during which the switch will wait for a
response from the authentication server.
no dot1x timeout
servertimeout
Set the default value.
dot1x timeout
silenceperiod
period
period: (60..65535)
seconds/not set
Set the client idle timeout after which the client becomes
unauthorized.
no dot1x timeout
silenceperiod
Set the default value.
Privileged EXEC mode commands
Command line prompt in the Privileged EXEC mode is as follows:
console#
Table 5.167. Privileged EXEC mode commands
Command
Value/Default value
Action
dot1x re-authenticate
[gigabitethernet
gi_port
|
tengigabitethernet
te_port
|
fortygigabitethernet
fo_port
| oob]
gi_port: (1..8/0/1..48);
te_port: (1..8/0/1..24);
fo_port: (1..8/0/1..4);
Enable manual re-authentication of the port specified
in the command or all ports supporting 802.1X.
show dot1x interface
gi_port: (1..8/0/1..48);
Show 802.1X state for the switch or selected