CLI Guide

Security Commands 1013
After an Access-Accept has been received by the switch and the switch grants
the host access to the network, it may take a few seconds before the DHCPv6
transaction completes. Use the aaa accounting delay-start command to delay
the sending of the Acct-Start packet to the accounting server.
Use the show authentication clients command to display the RADIUS server
supplied IPv6 address, if any.
RADIUS attribute 168 Framed-IPv6-Address is defined in RFC 6911.
Command History
Command introduced in firmware release 6.5.2.
authentication event fail retry
Use the authentication event fail retry command to select the number of
times authentication is reattempted by the user for an IEEE 802.1X
supplicant. Use the no form of the command to return the number of
maximum attempts to the default value.
Syntax
authentication event fail retry max-attempts
no authentication event fail retry
max-attempts — The number of times RADIUS authentication is allowed
to fail before failing the authentication and moving to the next
authentication method. Default 1. Range 1–5.
Default Configuration
By default, the number of failed authentication attempts is 1. An
authentication failure is declared failed after a single authentication attempt.
Command Mode
Interface Configuration mode, Interface Range mode
User Guidelines
This command is only applicable to IEEE 802.1X authentication with a
RADIUS server. It has no effect on any other authentication method.