Reference Guide

Table Of Contents
Term Definition
Transmit Period The timer used by the authenticator state machine on the specified port to determine
when to send an EAPOL EAP Request/Identity frame to the supplicant. The value is
expressed in seconds and will be in the range of 1 and 65535.
Guest-VLAN ID The guest VLAN identifier configured on the interface.
Guest VLAN Period The time in seconds for which the authenticator waits before authorizing and placing
the port in the Guest VLAN, if no EAPOL packets are detected on that port.
Supplicant Timeout The timer used by the authenticator state machine on this port to timeout the
supplicant. The value is expressed in seconds and will be in the range of 1 and 65535.
Server Timeout The timer used by the authenticator on this port to timeout the authentication server.
The value is expressed in seconds and will be in the range of 1 and 65535.
Maximum Requests The maximum number of times the authenticator state machine on this port will
retransmit an EAPOL EAP Request/Identity before timing out the supplicant. The value
will be in the range of 1 and 10.
Configured MAB Mode The administrative mode of the MAC authentication bypass feature on the switch.
Operational MAB Mode The operational mode of the MAC authentication bypass feature on the switch. MAB
might be administratively enabled but not operational if the control mode is not MAC
based.
Vlan-ID The VLAN assigned to the port by the RADIUS server. This is only valid when the port
control mode is not MAC-based.
VLAN Assigned Reason The reason the VLAN identified in the VLAN-assigned field has been assigned to the
port. Possible values are RADIUS, Unauthenticated VLAN, Guest VLAN, default, and Not
Assigned. When the VLAN Assigned Reason is Not Assigned, it means that the port has
not been assigned to any VLAN by dot1x. This only valid when the port control mode is
not MAC-based.
Reauthentication Period The timer used by the authenticator state machine on this port to determine when
reauthentication of the supplicant takes place. The value is expressed in seconds and will
be in the range of 1 and 65535.
Reauthentication
Enabled
Whether reauthentication is enabled on this port. Possible values are ‘True” or “False”.
Key Transmission
Enabled
Whether the key is transmitted to the supplicant for the specified port. Possible values
are True or False.
EAPOL Flood Mode
Enabled
Whether the EAPOL flood support is enabled on the switch. Possible values are True or
False.
Control Direction The control direction for the specified port or ports. Possible values are both or in.
Maximum Users The maximum number of clients that can get authenticated on the port in the MAC-
based dot1x authentication mode. This value is used only when the port control mode is
not MAC-based.
Unauthenticated VLAN
ID
The unauthenticated VLAN configured for this port. This value is valid for the port only
when the port control mode is not MAC-based.
Session Timeout The time for which the given session is valid. The time period in seconds is returned by
the RADIUS server on authentication of the port. This value is valid for the port only
when the port control mode is not MAC-based.
Session Termination
Action
This value indicates the action to be taken once the session timeout expires. Possible
values are Default and Radius-Request. If the value is Default, the session
is terminated the port goes into unauthorized state. If the value is Radius-Request,
Switching Commands
ExtremeSwitching 200 Series: Command Reference Guide for version 01 .02.04.0007 360