<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic N/S-Series MAC Authentication Failures will not Retry with Default Quietperiod in FAQs</title>
    <link>https://community.extremenetworks.com/t5/faqs/n-s-series-mac-authentication-failures-will-not-retry-with/m-p/46588#M405</link>
    <description>Article ID: 12933 &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Products&lt;/B&gt;&lt;BR /&gt;
Matrix N-Series DFE&lt;BR /&gt;
S-Series&lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Changes&lt;/B&gt;&lt;BR /&gt;
Enabled MAC Authentication ('&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;set macauthentication...&lt;/PRE&gt;&lt;/DIV&gt;', '&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;set radius...&lt;/PRE&gt;&lt;/DIV&gt;', '&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;set multiauth...&lt;/PRE&gt;&lt;/DIV&gt;').&lt;BR /&gt;
Users on one or more ports have failed authentication, for any reason.&lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Symptoms&lt;/B&gt;&lt;BR /&gt;
Authentication continues to fail for those users (= MACs), unless the failure is cleared from the port.&lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Cause&lt;/B&gt;&lt;BR /&gt;
Failed authentications (rejects received from the RADIUS server) are treated differently than other types of failures (timeouts, resource issues, etc.). The macauthentication quiet period is the key here and is set to &lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;0&lt;/PRE&gt;&lt;/DIV&gt; by default. &lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;0&lt;/PRE&gt;&lt;/DIV&gt; indicates "wait forever regardless of the port state transitions". If you set the quiet period to some other value you will see the same MAC that previously failed try to auth again after that period.&lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Solution/Workaround&lt;/B&gt;&lt;BR /&gt;
Functions as Designed (FAD).&lt;BR /&gt;
&lt;BR /&gt;
In operational networks, the quiet period is normally left at its default value. This is because machine-type authentications rarely fail, and when they do, there is usually a good reason - such as an unauthorized user attempting to gain network access.&lt;BR /&gt;
&lt;BR /&gt;
However, manipulation of this parameter can be helpful during MAC Authentication testing and deployment, to help speed up that process.&lt;BR /&gt;
&lt;BR /&gt;
To attempt &lt;I&gt;re&lt;/I&gt;authentication on a port, after some period of time:&lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;set macauthentication quietperiod&lt;/PRE&gt;&lt;/DIV&gt;  &lt;BR /&gt;
&lt;BR /&gt;
To clear a prior failure that has already occurred on the same port while &lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;quietperiod=0&lt;/PRE&gt;&lt;/DIV&gt;:&lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;clear multiauth station port&lt;/PRE&gt;&lt;/DIV&gt; &lt;BR /&gt;
&lt;BR /&gt;
See also: &lt;A href="http://bit.ly/1q7gmjz" target="_blank" rel="nofollow noreferrer noopener"&gt;7664&lt;/A&gt;.</description>
    <pubDate>Mon, 15 Sep 2014 18:31:00 GMT</pubDate>
    <dc:creator>FAQ_User</dc:creator>
    <dc:date>2014-09-15T18:31:00Z</dc:date>
    <item>
      <title>N/S-Series MAC Authentication Failures will not Retry with Default Quietperiod</title>
      <link>https://community.extremenetworks.com/t5/faqs/n-s-series-mac-authentication-failures-will-not-retry-with/m-p/46588#M405</link>
      <description>Article ID: 12933 &lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Products&lt;/B&gt;&lt;BR /&gt;
Matrix N-Series DFE&lt;BR /&gt;
S-Series&lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Changes&lt;/B&gt;&lt;BR /&gt;
Enabled MAC Authentication ('&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;set macauthentication...&lt;/PRE&gt;&lt;/DIV&gt;', '&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;set radius...&lt;/PRE&gt;&lt;/DIV&gt;', '&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;set multiauth...&lt;/PRE&gt;&lt;/DIV&gt;').&lt;BR /&gt;
Users on one or more ports have failed authentication, for any reason.&lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Symptoms&lt;/B&gt;&lt;BR /&gt;
Authentication continues to fail for those users (= MACs), unless the failure is cleared from the port.&lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Cause&lt;/B&gt;&lt;BR /&gt;
Failed authentications (rejects received from the RADIUS server) are treated differently than other types of failures (timeouts, resource issues, etc.). The macauthentication quiet period is the key here and is set to &lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;0&lt;/PRE&gt;&lt;/DIV&gt; by default. &lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;0&lt;/PRE&gt;&lt;/DIV&gt; indicates "wait forever regardless of the port state transitions". If you set the quiet period to some other value you will see the same MAC that previously failed try to auth again after that period.&lt;BR /&gt;
&lt;BR /&gt;
&lt;B&gt;Solution/Workaround&lt;/B&gt;&lt;BR /&gt;
Functions as Designed (FAD).&lt;BR /&gt;
&lt;BR /&gt;
In operational networks, the quiet period is normally left at its default value. This is because machine-type authentications rarely fail, and when they do, there is usually a good reason - such as an unauthorized user attempting to gain network access.&lt;BR /&gt;
&lt;BR /&gt;
However, manipulation of this parameter can be helpful during MAC Authentication testing and deployment, to help speed up that process.&lt;BR /&gt;
&lt;BR /&gt;
To attempt &lt;I&gt;re&lt;/I&gt;authentication on a port, after some period of time:&lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;set macauthentication quietperiod&lt;/PRE&gt;&lt;/DIV&gt;  &lt;BR /&gt;
&lt;BR /&gt;
To clear a prior failure that has already occurred on the same port while &lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;quietperiod=0&lt;/PRE&gt;&lt;/DIV&gt;:&lt;BR /&gt;
&lt;DIV class="threadCode"&gt;&lt;B&gt;code:&lt;/B&gt;&lt;PRE spellcheck="false"&gt;clear multiauth station port&lt;/PRE&gt;&lt;/DIV&gt; &lt;BR /&gt;
&lt;BR /&gt;
See also: &lt;A href="http://bit.ly/1q7gmjz" target="_blank" rel="nofollow noreferrer noopener"&gt;7664&lt;/A&gt;.</description>
      <pubDate>Mon, 15 Sep 2014 18:31:00 GMT</pubDate>
      <guid>https://community.extremenetworks.com/t5/faqs/n-s-series-mac-authentication-failures-will-not-retry-with/m-p/46588#M405</guid>
      <dc:creator>FAQ_User</dc:creator>
      <dc:date>2014-09-15T18:31:00Z</dc:date>
    </item>
  </channel>
</rss>

