dot1x timeout

Configures the timeout parameters that determine the time interval for client reauthentication and EAP retransmissions.

Syntax

dot1x timeout {re-authperiod seconds | supp-timeout seconds | tx-period seconds }
no dot1x timeout {re-authperiod seconds | supp-timeout seconds | tx-period seconds }

Command Default

The timeout parameters are not applied to the device.

Parameters

re-authperiod seconds
Specifies the interval at which clients connected to 802.1X authentication enabled ports are periodically reauthenticated. When periodic reauthentication is enabled using the dot1x reauthentication command, the device reauthenticates the clients every 3,600 seconds by default. The re-authperiod option allows you to specify the time interval between reauthentication attempts. The reauthentication interval configured using the dot1x timeout re-authperiod command takes precedence.
supp-timeout seconds
Specifies the EAP response timeout for 802.1x authentication. By default, when the device relays an EAP-Request frame from the RADIUS server to the client, it expects to receive a response from the client within 30 seconds. If the client does not respond within the allotted time, the device retransmits the EAP-Request frame to the client. The timeout value for retransmission of EAP-Request frames to the client can be configured using the supp-timeout seconds parameters.
tx-period seconds
Specifies the EAP request retransmission interval, in seconds, with the client. By default, if the device does not receive an EAP-response/identity frame from a client, the device waits 30 seconds, then retransmits the EAP-request/identity frame. You can optionally change the amount of time the device waits before re-transmitting the EAP-request/identity frame to the client. If the client does not send back an EAP-response/identity frame within 60 seconds, the device will transmit another EAP-request/identity frame. The tx-period is a value from 1 through 4294967295. The default is 30 seconds.

Modes

Interface configuration mode

Usage Guidelines

The no form of the command disables dot1x timeout.

Examples

The following example sets 25 seconds as the amount of time between reauthorization attempts on a specific interface.

device(config)# interface Ethernet 1/1
device(conf-if-eth-1/1)# dot1x timeout re-authperiod 25

The following example sets 45 seconds as the switch-to-client retransmission time for the EAP request frame on a specific interface.

device(config)# interface Ethernet 1/1
device(conf-if-eth-1/1)# dot1x timeout supp-timeout 45

The following example sets 34 seconds as the waiting period for a response to an EAP-request or identity frame from the client before retransmitting the request on a specific interface.

device(config)# interface Ethernet 1/1
device(conf-if-eth-1/1)# dot1x timeout tx-period 34