EOS NAC: What happen (in this config) when the RADIUS/NetSight Server (for MAC Auth Only) is not reachable?
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎08-30-2018 11:02 AM
Hello Community,
I'm looking for details if Clients connected to "auth-reg" Ports will still have connectivity, If the Radius/NetSight Server is offline?
set multiauth mode multi
set multiauth precedence mac quarantine-agent dot1x pwa cep radius-snooping auto-tracking
set multiauth port mode force-auth ge.1.1
set multiauth port mode force-auth ge.1.2
set multiauth port mode auth-reqd ge.1.3
set multiauth port mode force-auth ge.1.4
set multiauth port mode auth-reqd ge.1.5
[..]
Thanks,
Jan
I'm looking for details if Clients connected to "auth-reg" Ports will still have connectivity, If the Radius/NetSight Server is offline?
set multiauth mode multi
set multiauth precedence mac quarantine-agent dot1x pwa cep radius-snooping auto-tracking
set multiauth port mode force-auth ge.1.1
set multiauth port mode force-auth ge.1.2
set multiauth port mode auth-reqd ge.1.3
set multiauth port mode force-auth ge.1.4
set multiauth port mode auth-reqd ge.1.5
[..]
Thanks,
Jan
6 REPLIES 6
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎08-31-2018 10:39 AM
Force-auth = the port is authorized no authentication will happen
Auth-req = no traffic will pass until accept is received
the third option is authentication optional (auto) = if the auth is not successful then the default port config is used (vlan, default policy, QoS...)
You can have more radius servers = to accomplish HA
Auth-req = no traffic will pass until accept is received
the third option is authentication optional (auto) = if the auth is not successful then the default port config is used (vlan, default policy, QoS...)
You can have more radius servers = to accomplish HA
Regards
Zdeněk Pala
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Get Direct Link
- Report Inappropriate Content
‎08-30-2018 11:04 AM
BTW, with regards to auth-reqd VS. force-auth:
https://gtacknowledge.extremenetworks.com/articles/How_To/How-to-disable-authentication-on-a-port-to...
https://gtacknowledge.extremenetworks.com/articles/How_To/How-to-disable-authentication-on-a-port-to...
