1-18
The unicast trigger function is used for clients that cannot initiate authentication unsolicitedly and is
suitable for networks not requiring all the clients to be authenticated. Therefore, it is recommended to
disable the multicast trigger function when the unicast trigger function is enabled, so as to avoid sending
authentication packets to authenticated clients or clients requiring no authentication.
Specifying a Mandatory Authentication Domain for a Port
With a mandatory authentication domain specified for a port, the system uses the mandatory
authentication domain for authentication, authorization, and accounting of all 802.1X users on the port.
Follow these steps to specify a mandatory authentication domain for a port:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enter Ethernet interface view
interface
interface-type
interface-number
—
Specify a mandatory
authentication domain for the
port
dot1x mandatory-domain
domain-name
Required
Not specified by default
Enabling the Quiet Timer Function
After the quiet timer is enabled on the device, when a client fails 802.1X authentication, the device
refuses further authentication requests from the client in a period of time, which is specified by the quiet
timer (using the
dot1x timer quiet-period
command).
Follow these steps to enable the quiet timer:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Enable the quiet timer
dot1x quiet-period
Required
Disabled by default
Enabling the Re-Authentication Function
If periodic re-authentication is enabled on a port, the device will re-authenticate online users on the port
at the interval specified by the periodic re-authentication timer. This is intended to track the connection
status of online users and update the authorization attributes assigned by the server, such as the ACL,
VLAN, and QoS Profile, ensuring that the users are in normal online state.
Follow these steps to enable the periodic re-authentication function:
To do…
Use the command…
Remarks
Enter system view
system-view
—
Summary of Contents for S7906E - Switch
Page 82: ...1 4 DeviceA interface tunnel 1 DeviceA Tunnel1 service loopback group 1...
Page 200: ...1 11 DeviceB display vlan dynamic No dynamic vlans exist...
Page 598: ...ii...
Page 1757: ...4 9...
Page 1770: ...6 4...
Page 2017: ...2 11 Figure 2 3 SFTP client interface...
Page 2238: ...1 16 DeviceA cfd linktrace service instance 1 mep 1001 target mep 4002...