Chapter 13: Security Measures
Configuring 802.1X Port Authentication
– 342 –
•
Tx Period
– Sets the time period during an authentication session that
the switch waits before re-transmitting an EAP packet.
(Range: 1-65535; Default: 30 seconds)
•
Supplicant Timeout
– Sets the time that a switch port waits for a
response to an EAP request from a client before re-transmitting an EAP
packet. (Range: 1-65535; Default: 30 seconds)
This command attribute sets the timeout for EAP-request frames other
than EAP-request/identity frames. If dot1x authentication is enabled on
a port, the switch will initiate authentication when the port link state
comes up. It will send an EAP-request/identity frame to the client to
request its identity, followed by one or more requests for authentication
information. It may also send other EAP-request frames to the client
during an active connection as required for reauthentication.
•
Server Timeout
– Sets the time that a switch port waits for a response
to an EAP request from an authentication server before re-transmitting
an EAP packet. (Default: 0 seconds)
A RADIUS server must be set before the correct operational value of 10
seconds will be displayed in this field. (See
Authentication Servers” on page 264
.)
•
Re-authentication Status
– Sets the client to be re-authenticated
after the interval specified by the Re-authentication Period. Re-
authentication can be used to detect if a new device is plugged into a
switch port. (Default: Disabled)
•
Re-authentication Period
– Sets the time period after which a
connected client must be re-authenticated. (Range: 1-65535 seconds;
Default: 3600 seconds)
•
Re-authentication Max Retries
– The maximum number of times the
switch port will retransmit an EAP request/identity packet to the client
before it times out the authentication session. (Range: 1-10;
Default: 2)
•
Intrusion Action
– Sets the port’s response to a failed authentication.
•
Block Traffic
– Blocks all non-EAP traffic on the port. (This is the
default setting.)
•
Guest VLAN
– All traffic for the port is assigned to a guest VLAN.
The guest VLAN must be separately configured (See
) and mapped on each port (See
“Configuring Network Access for Ports” on page 285
).
Supplicant List
•
Supplicant
– MAC address of authorized client.
Authenticator PAE State Machine
Summary of Contents for SSE-G2252
Page 42: ...44 General IP Routing on page 627...
Page 603: ...Chapter 16 IP Configuration Setting the Switch s IP Address IP Version 6 609...
Page 883: ...Chapter 24 General Security Measures Port based Traffic Segmentation 894...
Page 989: ...Chapter 30 Congestion Control Commands Automatic Traffic Control Commands 1000 Console...
Page 1007: ...Chapter 33 Address Table Commands 1019...
Page 1137: ...Chapter 38 Quality of Service Commands 1150...