
Multi-Service IronWare Security Configuration Guide 315
53-1003035-02
Displaying 802.1x information
8
Brocade(config-dot1x)# auth-fail-max-attempts 2
Syntax: [no] auth-fail-max-attempts attempts
By default, the device makes 3 attempts to authenticate a client. You can specify between 1 – 10
authentication attempts.
Display commands
The show port security global-deny command lists all the configured global deny MAC addresses.
The show port security denied-macs command lists all the denied MAC addresses in the system.
Clearing a dot1x-mac-session for a MAC address
You can clear the dot1x-mac-session for a specified MAC address, so that the client with that MAC
address can be re-authenticated by the RADIUS server.
Brocade# clear dot1x mac-session 00e0.1234.abd4
Syntax: clear dot1x mac-session mac-address
Displaying 802.1x information
You can display the following 802.1x-related information:
• Information about the 802.1x configuration on the device and on individual ports
• Statistics about the EAPOL frames passing through the device
• Information about 802.1x-enabled ports dynamically assigned to a VLAN
• Information about the user-defined and dynamically applied Mac address and IP ACLs
currently active on the device
• Information about the 802.1x multiple client configuration
Displaying 802.1x configuration information
To display information about the 802.1x configuration on the device, enter the following command.
Syntax: show dot1x
Brocade# show dot1x
PAE Capability : Authenticator Only
system-auth-control : Enable
Number of ports enabled : 25
re-authentication : Disable
global-filter-strict-security: Enable
quiet-period : 60 Seconds
tx-period : 30 Seconds
supptimeout : 30 Seconds
servertimeout : 30 Seconds
maxreq : 3
re-authperiod : 3600 Seconds
Protocol Version : 1
auth-fail-action : Block Traffic
MAC Session Aging : All
MAC Session Max Age : 120 Seconds
Maximum Failed Attempts : 3
Comentarios a estos manuales