beautypg.com

Displaying 802.1x information, Displaying 802.1x configuration information, Clearing a dot1x-mac-session for a – Brocade Multi-Service IronWare Security Configuration Guide (Supporting R05.6.00) User Manual

Page 333: Mac address, Display commands, Clearing a dot1x-mac-session for a mac address

background image

Multi-Service IronWare Security Configuration Guide

315

53-1003035-02

Displaying 802.1x information

8

Brocade(config-dot1x)# auth-fail-max-attempts 2

Syntax: [no] auth-fail-max-attempts attempts

By default, the device makes 3 attempts to authenticate a client. You can specify between 1 – 10
authentication attempts.

Display commands

The show port security global-deny command lists all the configured global deny MAC addresses.

The show port security denied-macs command lists all the denied MAC addresses in the system.

Clearing a dot1x-mac-session for a MAC address

You can clear the dot1x-mac-session for a specified MAC address, so that the client with that MAC
address can be re-authenticated by the RADIUS server.

Brocade# clear dot1x mac-session 00e0.1234.abd4

Syntax: clear dot1x mac-session mac-address

Displaying 802.1x information

You can display the following 802.1x-related information:

Information about the 802.1x configuration on the device and on individual ports

Statistics about the EAPOL frames passing through the device

Information about 802.1x-enabled ports dynamically assigned to a VLAN

Information about the user-defined and dynamically applied Mac address and IP ACLs
currently active on the device

Information about the 802.1x multiple client configuration

Displaying 802.1x configuration information

To display information about the 802.1x configuration on the device, enter the following command.

Syntax: show dot1x

Brocade# show dot1x

PAE Capability : Authenticator Only

system-auth-control : Enable

Number of ports enabled : 25

re-authentication : Disable

global-filter-strict-security: Enable

quiet-period : 60 Seconds

tx-period : 30 Seconds

supptimeout : 30 Seconds

servertimeout : 30 Seconds

maxreq : 3

re-authperiod : 3600 Seconds

Protocol Version : 1

auth-fail-action : Block Traffic

MAC Session Aging : All

MAC Session Max Age : 120 Seconds

Maximum Failed Attempts : 3