802.1x Timers

The 802.1x authentication procedure is controlled by a number of configurable timers and scalars. There are two separate sets, one for the EAPOL message exchange and one for the RADIUS message exchange. See Figure 1 for an example of the timers on the 7750 SR.

Figure 1. 802.1x EAPOL Timers (left) and RADIUS Timers (right)

EAPOL timers:

RADIUS timer and scaler:

The router can also be configured to periodically trigger the authentication procedure automatically. This is controlled by the enable re-authentication and re-auth-period parameters. Reauth-period indicates the period in seconds (since the last time that the authorization state was confirmed) before a new authentication procedure is started. The range of reauth-period is 1 to 9000 seconds (the default is 3600 seconds, one hour). Note that the port stays in an authorized state during the re-authentication procedure.