< Home

authentication critical eapol-success

Function

The authentication critical eapol-success command configures the device to send an EAPoL-Success packet to a user after the user is added to the critical VLAN.

The undo authentication critical eapol-success command configures the device to send an EAPoL-Fail packet to a user after the user is added to the critical VLAN.

By default, an EAPoL-Fail packet is sent to a user after the user is added to the critical VLAN.

Format

In the system view:

authentication critical eapol-success interface { interface-type interface-number1 [ to interface-number2 ] } &<1-10>

undo authentication critical eapol-success interface { interface-type interface-number1 [ to interface-number2 ] } &<1-10>

In the interface view:

authentication critical eapol-success

undo authentication critical eapol-success

Parameters

Parameter

Description

Value

interface { interface-type interface-number1 [ to interface-number2 ] }

Specifies the interface type and number.

  • interface-type specifies the interface type.
  • interface-number1 specifies the number of the first interface.
  • interface-number2 specifies the number of the last interface.

-

Views

System view, Ethernet interface view, GE interface view, MultiGE interface view, XGE interface view, 25GE interface view, 40GE interface view, 100GE interface view, Eth-Trunk interface view, Port group view

Default Level

2: Configuration level

Usage Guidelines

After a user is added to the critical VLAN because the authentication server does not respond, the device can be configured to send an EAPoL-Success or EAPoL-Fail packet to the user to prevent the user from continuously sending access request packets. After receiving the EAPoL-Success packet or EAPoL-Fail packet, the user stops attempting to go online by sending the access request packet repeatedly, which prevents the device performance from degrading.

The user receiving the EAPoL-Success packet can still obtain the IP address through a DHCP packet, while the user receiving the EAPoL-Fail packet fails to do so. The administrator can configure the device to send an EAPoL-Success or EAPoL-Fail packet as required.

Example

# Configure the device to send an EAPoL-Success packet to a user after the user is added to the critical VLAN on GE0/0/1.

<HUAWEI> system-view
[HUAWEI] interface gigabitethernet 0/0/1
[HUAWEI-GigabitEthernet0/0/1] authentication critical eapol-success
Copyright © Huawei Technologies Co., Ltd.
Copyright © Huawei Technologies Co., Ltd.
< Previous topic Next topic >