Operation Manual – 802.1x and System Guard
H3C S5600 Series Ethernet Switches
Chapter 1 802.1x Configuration
1-24
1) The switch uses the value of the Session-timeout attribute field of the
Access-Accept packet sent by the RADIUS server as the re-authentication
interval.
2) The switch uses the value configured with the
dot1x timer reauth-period
command as the re-authentication interval for access users.
Note the following:
During re-authentication, the switch always uses the latest re-authentication interval
configured, no matter which of the above-mentioned two ways is used to determine the
re-authentication interval. For example, if you configure a re-authentication interval on
the switch and the switch receives an Access-Accept packet whose Termination-Action
attribute field is 1, the switch will ultimately use the value of the Session-timeout
attribute field as the re-authentication interval.
The following introduces how to configure the 802.1x re-authentication timer on the
switch.
Follow these steps to configure the re-authentication interval:
To do...
Use the command...
Remarks
Enter system view
system-view
—
Configure a
re-authentication interval
dot1x
timer
reauth-period
reauth-period-value
Optional
By default, the
re-authentication interval
is 3,600 seconds.
1.5 Displaying and Maintaining 802.1x Configuration
To do...
Use the command...
Remarks
Display the configuration,
session, and statistics
information about 802.1x
display dot1x
[
sessions
|
statistics
] [
interface
interface-list
]
Available in any view
Clear 802.1x-related
statistics information
reset dot1x statistics
[
interface interface-list
]
Available in user view
1.6 Configuration Example
1.6.1 802.1x Configuration Example
I. Network requirements
z
Authenticate users on all ports to control their accesses to the Internet. The switch
operates in MAC-based access control mode.