Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Dell EMC Configuration Guide for the S3100 Series 9.14.2.4

PDF

Terminating the 802.1x user session

Dell EMC Networking OS provides RADIUS extension commands that terminate the 802.1x user session. When this request is initiated, the NAS disconnects the 802.1x user session without disabling the physical port that authenticated the current session.

Before terminating the 802.1x user session, ensure that the following prerequisites are satisfied:
  • Shared key is configured in NAS for DAC.
  • NAS server listens on the Management IP UDP port 3799 (default) or the port configured through CLI.
  • The user is logged-in through 802.1X enabled physical port and successfully authenticated with Radius Server.
NAS uses the calling-station-id or the NAS-port attributes to identify the 802.1x session. In case of the EAP and MAB users, the calling-station-id is the MAC address of the supplicant and the NAS-port attribute is the interface identifier. Using these atrributes, the NAS retrieves the supplicant that is connected to the interface.
  1. Enter the following command to configure the dynamic authorization feature:
    radius dynamic-auth
  2. Enter the following command to terminate the 802.1x user session:
    terminate-session
    NAS terminates the 802.1x user session without disabling the physical port.
Dell(conf#)radius dynamic-auth
Dell(conf-dynamic-auth#)terminate-session
NAS takes the following actions whenever session termination is triggered:
  • validates the DM request and the session identification attributes.
  • sends a DM-Nak with an error-cause of 402 (missing attribute), if the DM request does not contain the calling-station-id and NAS-port attributes.
  • returns an error-cause value of 503 (session context not found), if it is not able to retrieve the session using the calling-station-id or NAS-port attribute or both.
  • sends a DM-Ack, if it is able to terminate the session.
  • sends a DM-Nak with an error-cause value of 506 (resource unavailable), if it is not able to apply changes to the existing session.
  • discards the packet, if simultaneous requests are received for the same NAS-port or calling-station-id, or both.

Rate this content

Accurate
Useful
Easy to understand
Was this article helpful?
0/3000 characters
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please provide ratings (1-5 stars).
  Please select whether the article was helpful or not.
  Comments cannot contain these special characters: <>()\