89
Configuration guidelines
When you configure the online user handshake feature, follow these restrictions and guidelines:
•
The SmartOn feature and the online user handshake feature are mutually exclusive. Before you
enable the online user handshake feature, make sure the SmartOn feature is disabled.
•
To use the online user handshake security feature, make sure the online user handshake
feature is enabled.
•
The online user handshake security feature takes effect only on the network where the iNode
client and IMC server are used.
•
If the network has 802.1X clients that cannot exchange handshake packets with the access
device, disable the online user handshake feature. This operation prevents the 802.1X
connections from being incorrectly torn down.
•
Enable the online user handshake reply feature only if 802.1X clients will go offline without
receiving EAP-Success packets from the device.
Configuration procedure
To configure the online user handshake feature:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
(Optional.) Set the
handshake timer.
dot1x timer
handshake-period
handshake-period-value
The default is 15 seconds.
3.
Enter Layer 2 Ethernet
interface view.
interface
interface-type
interface-number
N/A
4.
Enable the online user
handshake feature.
dot1x handshake
By default, the feature is enabled.
5.
(Optional.) Enable the online
user handshake security
feature.
dot1x handshake secure
By default, the feature is disabled.
6.
(Optional.) Enable the
802.1X online user
handshake reply feature.
dot1x handshake reply enable
By default, the device does not
reply to 802.1X clients'
EAP-Response/Identity packets
during the online handshake
process.
Configuring the authentication trigger feature
The authentication trigger feature enables the access device to initiate 802.1X authentication when
802.1X clients cannot initiate authentication.
This feature provides the multicast trigger and unicast trigger (see 802.1X authentication initiation in
"802.1X overview").
Configuration guidelines
When you configure the authentication trigger feature, follow these guidelines:
•
Enable the multicast trigger on a port when the clients attached to the port cannot send
EAPOL-Start packets to initiate 802.1X authentication.
Summary of Contents for 10500 series
Page 326: ...312 No duration limit for this SA ...