107
Setting MAC authentication timers
MAC authentication uses the following timers:
•
Offline detect timer
—Sets the interval that the device waits for traffic from a user before the device
regards the user idle. If a user connection has been idle within the interval, the device logs the user
out and stops accounting for the user.
•
Quiet timer
—Sets the interval that the device must wait before the device can perform MAC
authentication for a user who has failed MAC authentication. All packets from the MAC address are
dropped during the quiet time. This quiet mechanism prevents repeated authentication from
affecting system performance.
•
Server timeout timer
—Sets the interval that the device waits for a response from a RADIUS server
before the device regards the RADIUS server unavailable. If the timer expires during MAC
authentication, the user cannot access the network.
To set MAC authentication timers:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Set MAC authentication
timers.
mac-authentication
timer
{
offline-detect
offline-detect-value
|
quiet
quiet-value
|
server-timeout
server-timeout-value
}
By default, the offline detect
timer is 300 seconds, the quiet
timer is 60 seconds, and the
server timeout timer is 100
seconds.
Setting the maximum number of concurrent MAC
authentication users on a port
Perform this task to prevent the system resources from being overused.
To set the maximum number of concurrent MAC authentication users on a port:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter Layer 2 Ethernet interface
view.
interface
interface-type
interface-number
N/A
3.
Set the maximum number of
concurrent MAC authentication
users on the port
mac-authentication max-user
user-number
The default setting is
2048
.