Use the Add Authentication Profiles page in Customer Portal to add authentication profiles.
Adding an authentication profile involves the following steps:
Define the primary and secondary methods for authenticating a supplicant—802.1x (dot1x), MAC RADIUS.
Define the action that the port must take when the RADIUS server is not reachable or a user is not authenticated (fallback options).
Define the authentication process parameters, such as the number of times that the switch can request for user authentication, whether a user must be reauthenticated at regular intervals, the number of times a switch can attempt to contact the RADIUS server for authenticating a user, and so on.
To add an authentication profile:
The Authentication Profiles page appears, displaying the existing authentication profiles.
The Add Authentication Profiles wizard appears.
Note Fields marked with * are mandatory.
An authentication profile is added. You are returned to the Authentication Profiles page where a confirmation message is displayed.
After you add an authentication profile, you can assign it to a port profile. See Add Port Profiles.
Table 228: Fields on the Add Authentication Profile Page
Setting | Guideline |
---|---|
General | |
Profile Name | Enter a unique name for the authentication profile, which can only contain alphanumeric characters and hyphen (-); 15-character maximum. |
Profile Description | Enter a description for the authentication profile. |
Supplicant Mode | Select a mode for authenticating the supplicant:
|
Authentication Method | |
Primary Method | Select the primary method of authenticating a supplicant:
|
Secondary Method | The secondary method for authenticating a supplicant when the switch is unable to validate a supplicant by using the primary method:
|
Fallback Options You can configure authentication fallback options to specify how supplicants connected to a switch are supported if the RADIUS authentication server becomes unavailable or sends a RADIUS access-reject message. | |
Server Fail | Select an action that the switch applies to supplicants when the authentication servers are not reachable. The switch can accept or deny access to supplicants or maintain the access already granted to supplicants before the RADIUS timeout occurred. You can also configure the switch to move the supplicants to a specific VLAN.
|
VLAN ID | If you select VLAN ID for the Server Fail option, enter the VLAN ID of the VLAN to which the supplicant must be assigned. |
Server Reject | The action the switch takes when the switch is unable to validate a supplicant because of incorrect credentials provided by the supplicant:
|
VLAN ID | If you select VLAN ID for the Server Reject option, enter the VLAN ID to which the supplicant must be assigned. |
Guest | Select an action to be taken for a guest (corporate guest or supplicants that are not 802.1x enabled).
|
VLAN ID | Enter the VLAN ID of the guest VLAN. |
Advanced Settings | |
Transmit Period | Enter the number of seconds that the switch waits before retransmitting the initial authentication request to the supplicant. Range: 1 through 65,535 seconds. Default: 30 seconds. |
Maximum Requests | Enter the maximum number of times that authentication request packets are retransmitted to a supplicant before the authentication session times out. Range: 1 through 10. Default: 2. |
Retries | Enter the number of times that the switch attempts to contact an authentication server for authenticating a supplicant after an initial failure. Range: 1 through 10. Default: 3. |
Quiet Period | Enter the number of seconds that the port remains in the wait state following a failed authentication exchange with the supplicant, before reattempting authentication. Range: 0 through 65,535 seconds. Default: 3 seconds. |
Reauthentication | Click to enable or disable (default) reauthentication of the supplicant after a specified interval. If you enable this option, you must provide the reauthentication interval. |
Reauthentication Interval | If you enable reauthentication, enter the number of seconds after which a supplicant must be reauthenticated. Range: 1 through 65,535 seconds. Default: 3600 seconds. |
Supplicant Timeout | Enter the number of seconds that the port must wait for a response from the supplicant, before considering a timing out and resending the request. Range: 1 through 60 seconds. Default: 30 seconds. |
RADIUS Server Timeout | Enter the number of seconds that the port waits for a reply from the RADIUS server when authenticating a supplicant before timing out and invoking the server-fail action (action that the switch applies to supplicants when the authentication servers are not reachable). Range: 1 through 60 seconds. Default: 30 seconds. |