mac-authentication timer guest-vlan-reauth

Syntax

mac-authentication timer guest-vlan-reauth interval

undo mac-authentication timer guest-vlan-reauth

View

System view

Default level

2: System level

Parameters

interval: Sets the MAC re-authentication timer for users in the MAC authentication guest VLAN. The value range for this argument is 1 to 3600, in seconds.

Description

Use mac-authentication timer guest-vlan-reauth to set the MAC re-authentication timer for users in the MAC authentication guest VLAN. When the MAC re-authentication timer expires, the device re-authenticates the users in the MAC authentication guest VLAN.

Use undo mac-authentication timer guest-vlan-reauth to restore the default.

By default, the MAC re-authentication timer is 30 seconds for users in the MAC authentication guest VLAN.

For this command to take effect, you must also configure the MAC authentication guest VLAN.

The quiet timer takes precedence over the MAC re-authentication timer. If the quiet timer is set longer than the MAC re-authentication timer, the MAC re-authentication timer does not take effect.

The device handles VLANs for users in the MAC authentication guest VLAN based on the following rules:

Authentication status

VLAN manipulation

A user fails MAC re-authentication because of unreachable servers.

  • If a MAC authentication critical VLAN is available, the device assigns the user to the critical VLAN.

  • If no MAC authentication critical VLAN is configured, the user is still in the MAC authentication guest VLAN. The MAC re-authentication timer restarts for the user.

A user fails MAC re-authentication for any other reasons except for unreachable servers.

The user is still in the MAC authentication guest VLAN. The MAC re-authentication timer restarts for the user.

A user passes MAC re-authentication.

  • The device removes the user from the MAC authentication guest VLAN and assigns the user to the authorization VLAN.

  • If the authentication server does not authorize a VLAN, the user is assigned to the initial VLAN. The initial VLAN refers to the VLAN to which the user belongs before it was assigned to the MAC authentication guest VLAN.

Related commands: mac-authentication guest-vlan

Examples

# Set the MAC re-authentication timer to 60 seconds for users in the MAC authentication guest VLAN.

<Sysname> system-view
[Sysname] mac-authentication timer guest-vlan-reauth 60