Use the Add Authentication Profiles page in the Customer Portal to add authentication profiles.
To add an authentication profile, you must:
Define the primary and secondary methods for authenticating a supplicant—dot1x, MAC RADIUS.
Define the action, the port must take, when the RADIUS server is not reachable or a user is not authenticated (fallback options).
Define the authentication process parameters, such as number of times the switch can request for user authentication, whether a user must be reauthenticated at regular intervals, number of times a switch can attempt to contact the RADIUS server for authenticating a user, and so on.
To add an authentication profile:
The Authentication Profiles page appears, displaying the configured authentication profiles.
The Add Authentication Profiles wizard appears.
Note Fields marked with * are mandatory.
An authentication profile is created. You are returned to the Authentication Profiles page where a confirmation message is displayed.
After you create an authentication profile, you can assign it to the port profile. See Add Port Profiles.
Table 221: Fields on the Add Authentication Profile Page
Setting | Guideline |
---|---|
General | |
Profile Name | Enter a unique name for the authentication profile, which can only contain alphanumeric characters and hyphen (-); 15-characters maximum. |
Profile Description | Enter a description for the authentication profile. |
Supplicant Mode | Select a mode for authenticating the supplicant:
|
Authentication Method | |
Primary Method | Select the primary method of authenticating a supplicant:
|
Secondary Method | The secondary method for authenticating a supplicant when the switch is unable to validate a supplicant by using the primary method:
|
Fallback Options You can configure authentication fallback options to specify how supplicants connected to a switch are supported if the RADIUS authentication server becomes unavailable or sends a RADIUS access-reject message. | |
Server Fail | Select an action that the switch applies to supplicants when the authentication servers are unavailable. The switch can accept or deny access to supplicants or maintain the access already granted to supplicants before the RADIUS timeout occurred. You can also configure the switch to move the supplicants to a specific VLAN.
|
VLAN ID | If you select VLAN ID for the Server Fail option, enter the VLAN ID of the VLAN to which the supplicant must be assigned. |
Server Reject | The action the switch takes when the switch is unable to validate a supplicant because of incorrect credentials provided by the supplicant:
|
VLAN ID | If you select VLAN ID for the Server Reject option, enter the VLAN ID to which the supplicant must be assigned. |
Guest | Select an action to be taken for a guest. A guest can be:
Select one of the following actions:
|
VLAN ID | Enter the VLAN ID of the guest VLAN. |
Advanced Settings | |
Transmit Period | Enter the number of seconds the switch waits before retransmitting the initial authentication request to the supplicant. Range: 1 through 65,535 seconds Default: 30 seconds |
Maximum Requests | Enter the maximum number of times authentication request packets are retransmitted to a supplicant before the authentication session times out. Range: 1 through 10 Default: 2 |
Retries | Enter the number of times the switch attempts to contact an authentication server for authenticating a supplicant after an initial failure. Range: 1 through 10 Default: 3 |
Quiet Period | Enter the number of seconds the port remains in the wait state following a failed authentication exchange with the supplicant, before reattempting authentication. Range: 0 through 65,535 seconds Default: 3 seconds |
Reauthentication | Click to enable or disable (default) reauthentication of the supplicant after a specified interval. If you enable this option, you must provide the reauthentication interval. |
Reauthentication Interval | If you enable reauthentication, enter the number of seconds after which a supplicant must be reauthenticated. Range: 1 through 65,535 seconds Default: 3600 seconds |
Supplicant Timeout | Enter the number of seconds the port must wait for a response from the supplicant, before considering a timeout and resending the request. Range: 1 through 60 seconds Default: 30 seconds |
RADIUS Server Timeout | Enter the number of seconds the port waits for a reply from the RADIUS server when authenticating a supplicant before timing out and invoking the server-fail action. Range: 1 through 60 seconds Default: 30 seconds |