Users Guide

Security Commands 954
Syntax
authentication violation { protect | restrict | shutdown }
no authentication violation
protect—Drop incoming packets from the offending host.
restrict—Generate a log when a violation occurs.
shutdown—Error disable the interface.
Default Configuration
The default violation mode is restrict.
Command Mode
Interface (Ethernet) Configuration mode
User Guidelines
This command should not be confused with the port security capability.
These actions occur solely within the authentication framework.
Command History
Syntax added in version 6.6 firmware.
Example
The following example configures an interface error disable when a second
data user attempts to authenticate.
console(config-vlan100)#interface gi1/0/1
console(config-if-Gi1/0/1)#authentication port-control auto
console(config-if-Gi1/0/1)#authentication host-mode single-host
console(config-if-Gi1/0/1)#authentication violation shutdown
clear (IAS)
Use the clear aaa ias-users command to delete all IAS users.
Syntax
clear aaa ias-users