Users Guide

Security Commands 1065
Command Mode
Global Configuration mode
User Guidelines
Local processing of IEEE 802.1x frames must be disabled (no dot1x system-
auth-control) for this capability to be enabled. This capability is useful in
situations where the authenticator device is placed one or more hops away
from the authenticating host. The intervening switch will flood all received
IEEE 802.1x frames in the VLAN.
Flooding of IEEE 802.1x frames makes end stations vulnerable to a denial of
service attack should another end station record and play back certain flooded
EAPOL frames at a high rate.
clear authentication sessions
Use this command to clear all or some authentication sessions. Authenticated
clients must authenticate to the switch to gain access to network resources.
Syntax
clear authentication sessions [interface interface-id]
interface-id—An optional physical (Ethernet) interface identifier.
Default Configuration
This command has no default configuration.
Command Mode
Privileged Exec mode
User Guidelines
When used with no parameters, this command clears all 802.1X sessions on
the switch by removing the authentication information, reseting the 802.1X
state machine and denying network access to the authenticated device. Use
with caution.