4-16
tx-period-value
: Setting for the username request timeout timer in seconds. It ranges from 10 to 120
and defaults to 30.
Description
Use the
dot1x
timer
command to set 802.1X timers.
Use the
undo dot1x
timer
command to restore the defaults.
Several timers are used in the 802.1X authentication process to guarantee that the supplicants, the
authenticators, and the RADIUS server interact with each other in a reasonable manner. You can use
this command to set these timers:
z
Handshake timer (handshake-period): After a supplicant passes authentication, the authenticator
sends to the supplicant handshake requests at this interval to check whether the supplicant is
online. If the authenticator receives no response after sending the allowed maximum number of
handshake requests, it considers that the supplicant is offline.
z
Quiet timer (quiet-period): When a supplicant fails the authentication, the authenticator refuses
further authentication requests from the supplicant in this period of time.
z
Periodic re-authentication timer (reauth-period): If you enable periodic re-authentication on a port
(by the
dot1x re-authenticate
command), the device will re-authenticate online users on the port
at the interval specified by this timer. If you change the re-authentication interval when there are
users online, the device will continue to re-authenticate such users according to the original
re-authentication interval setting for one time. Then the device will use the new interval for
re-authentication of all online users.
z
Server timeout timer (server-timeout): Once an authenticator sends a RADIUS Access-Request
packet to the authentication server, it starts this timer. If this timer expires but it receives no
response from the server, it retransmits the request.
z
Supplicant timeout timer (supp-timeout): Once an authenticator sends an EAP-Request/MD5
Challenge frame to a supplicant, it starts this timer. If this timer expires but it receives no response
from the supplicant, it retransmits the request.
z
Username request timeout timer (tx-period): Once an authenticator sends an
EAP-Request/Identity frame to a supplicant, it starts this timer. If this timer expires but it receives
no response from the supplicant, it retransmits the request. In addition, to be compatible with
clients that do not send EAPOL-Start requests unsolicitedly, the device multicasts
EAP-Request/Identity frame periodically to detect the clients, with the multicast interval defined by
tx-period.
It is unnecessary to change the timers unless in some special or extreme network environments. The
change of a timer takes effect immediately.
Related commands:
display dot1x
.
Examples
# Set the server timeout timer to 150 seconds.
<Sysname> system-view
[Sysname] dot1x timer server-timeout 150
reset dot1x statistics
Syntax
reset dot1x statistics
[
interface
interface-list
]
Summary of Contents for E4510-48G
Page 109: ...2 18 Sysname interface bridge aggregation 1 Sysname Bridge Aggregation1 shutdown ...
Page 309: ...6 4 Sysname interface vlan interface 1 Sysname Vlan interface1 ip address dhcp alloc ...
Page 324: ...8 3 Sysname interface vlan interface 1 Sysname Vlan interface1 ip address bootp alloc ...
Page 530: ...2 5 Sysname mvlan 100 subvlan 10 to 15 ...
Page 739: ...8 15 Sysname system view Sysname port security trap addresslearned ...
Page 819: ...13 11 Sysname system view Sysname public key peer key2 import sshkey key pub ...
Page 914: ...5 17 Sysname reset oam ...
Page 1064: ...5 30 Slot 2 Set next configuration file successfully ...
Page 1325: ...21 13 Examples Redirect to member 2 Sysname irf switch to 2 Sysname Slave 2 ...