CLI Guide

Security Commands 1068
User Guidelines
Local processing of IEEE 802.1x frames must be disabled (no dot1x system-
auth-control) for this capability to be enabled. This capability is useful in
situations where the authenticator device is placed one or more hops away
from the authenticating host. The intervening switch will flood all received
IEEE 802.1x frames in the VLAN.
Flooding of IEEE 802.1x frames makes end stations vulnerable to a denial of
service attack should another end station record and play back certain flooded
EAPOL frames at a high rate.
clear authentication sessions
Use this command to clear all or some authentication sessions. Authenticated
clients must authenticate to the switch to gain access to network resources.
Syntax
clear authentication sessions [interface interface-id]
interface-id—An optional physical (Ethernet) interface identifier.
Default Configuration
This command has no default configuration.
Command Mode
Privileged Exec mode
User Guidelines
When used with no parameters, this command clears all 802.1X sessions on
the switch by removing the authentication information, reseting the 802.1X
state machine and denying network access to the authenticated device. Use
with caution.
When used with an interface parameter, this command clears all 802.1X
sessions on the interface by removing the authentication information,
reseting the 802.1X state machine, and denying network access to the
authenticated device. Use with caution.