
Operation Manual – 802.1x and System Guard
H3C S3100-52P Ethernet switch
Chapter 1 802.1x Configuration
1-13
II. Checking the client version
With the 802.1x client version-checking function enabled, a switch checks the version
and validity of an 802.1x client to prevent unauthorized users or users with earlier
versions of 802.1x client from logging in.
This function makes the switch to send version-requesting packets again if the 802.1x
client fails to send version-reply packet to the switch when the version-checking timer
times out.
Note:
The 802.1x client version-checking function needs the support of H3C’s 802.1x client
program.
III. The guest VLAN function
The guest VLAN function enables supplicant systems that are not authenticated to
access network resources in a restrained way.
The guest VLAN function enables supplicant systems that do not have 802.1x client
installed to access specific network resources. It also enables supplicant systems that
are not authenticated to upgrade their 802.1x client programs.
With this function enabled:
z
The switch sends authentication triggering request (EAP-Request/Identity)
packets to all the 802.1x-enabled ports.
z
After the maximum number retries have been made and there are still ports that
have not sent any response back, the switch will then add these ports to the guest
VLAN.
z
Users belonging to the guest VLAN can access the resources of the guest VLAN
without being authenticated. But they need to be authenticated when accessing
external resources.
Normally, the guest VLAN function is coupled with the dynamic VLAN delivery function.
Refer to
AAA Operation
for detailed information about the dynamic VLAN delivery
function.
IV. Enabling 802.1x re-authentication
802.1x re-authentication is timer-triggered or packet-triggered. It re-authenticates users
who have passed authentication. With 802.1x re-authentication enabled, the switch can
monitor the connection status of users periodically. If the switch receives no
re-authentication response from a user in a period of time, it tears down the connection