724
C
HAPTER
50: 802.1
X
C
ONFIGURATION
multicasts EAP-Request/Identity frames to the supplicant system at an interval
defined by this timer.
■
Supplicant timeout timer (supp-timeout): Once an authenticator sends an
EAP-Request/MD5 Challenge frame to a supplicant, it starts this timer. If this
timer expires but it receives no response from the supplicant, it retransmits the
request.
■
Server timeout timer (server-timeout): Once an authenticator sends a RADIUS
Access-Request packet to the authentication server, it starts this timer. If this
timer expires but it receives no response from the server, it retransmits the
request.
■
Handshake timer (handshake-period): After a supplicant passes authentication,
the authenticator sends to the supplicant handshake requests at this interval to
check whether the supplicant is online. If the authenticator receives no
response after sending the allowed maximum number of handshake requests,
it considers that the supplicant is offline.
■
Quiet timer (quiet-period): When a supplicant fails the authentication, the
authenticator refuses further authentication requests from the supplicant in
this period of time.
Implementation of
802.1x in the Devices
The devices extend and optimize the mechanism that the 802.1x protocol specifies
by:
■
Allowing multiple users to access network services through the same physical
port.
■
Supporting two authentication methods:
portbased
and
macbased
. With the
portbased
method, after the first user of a port passes authentication, all
other users of the port can access the network without authentication, and
when the first user goes offline, all other users get offline at the same time.
With the
macbased
method, each user of a port must be authenticated
separately, and when an authenticated user goes offline, no other users are
affected.
n
After an 802.1x supplicant passes authentication, the authentication server sends
authorization information to the authenticator. If the authorization information
contains VLAN authorization information, the authenticator adds the port
connecting the supplicant to the assigned VLAN. This neither changes nor affects
the configurations of the port. The only result is that the assigned VLAN takes
precedence over the manually configured one, that is, the assigned VLAN takes
effect. After the supplicant goes offline, the configured one takes effect.
Features Working
Together with 802.1x
VLAN assigning
After an 802.1x user passes the authentication, the server will send an
authorization message to the device. If the server is enabled with the VLAN
assigning function, the assigned VLAN information will be included in the
message. The device, depending on the link type of the port used to log in, adds
the port to the assigned VLAN according to the following rules:
■
If the port link type is Access, the port leaves its current VLAN and joins the
assigned VLAN.
■
If the port link type is Trunk, the assigned VLAN is allowed to pass the current
trunk port. The default VLAN ID of the port is that of the assigned VLAN.
Содержание 4800G Series
Страница 26: ...26 CHAPTER NETWORKING APPLICATIONS ...
Страница 30: ...30 CHAPTER 1 LOGGING IN TO AN ETHERNET SWITCH ...
Страница 62: ...62 CHAPTER 3 LOGGING IN THROUGH TELNET ...
Страница 70: ...70 CHAPTER 5 LOGGING IN THROUGH WEB BASED NETWORK MANAGEMENT SYSTEM ...
Страница 72: ...72 CHAPTER 6 LOGGING IN THROUGH NMS ...
Страница 82: ...82 CHAPTER 8 CONTROLLING LOGIN USERS ...
Страница 98: ...98 CHAPTER 9 VLAN CONFIGURATION ...
Страница 108: ...108 CHAPTER 10 VOICE VLAN CONFIGURATION ...
Страница 119: ...GVRP Configuration Examples 119 DeviceB display vlan dynamic No dynamic vlans exist ...
Страница 120: ...120 CHAPTER 11 GVRP CONFIGURATION ...
Страница 160: ...160 CHAPTER 17 PORT ISOLATION CONFIGURATION ...
Страница 172: ...172 CHAPTER 19 LINK AGGREGATION CONFIGURATION ...
Страница 196: ...196 CHAPTER 22 DLDP CONFIGURATION ...
Страница 240: ...240 CHAPTER 23 MSTP CONFIGURATION ...
Страница 272: ...272 CHAPTER 27 RIP CONFIGURATION ...
Страница 364: ...364 CHAPTER 29 IS IS CONFIGURATION ...
Страница 426: ...426 CHAPTER 31 ROUTING POLICY CONFIGURATION ...
Страница 442: ...442 CHAPTER 33 IPV6 RIPNG CONFIGURATION ...
Страница 466: ...466 CHAPTER 35 IPV6 IS IS CONFIGURATION ...
Страница 488: ...488 CHAPTER 36 IPV6 BGP CONFIGURATION ...
Страница 498: ...498 CHAPTER 37 ROUTING POLICY CONFIGURATION ...
Страница 540: ...540 CHAPTER 40 TUNNELING CONFIGURATION ...
Страница 552: ...552 CHAPTER 41 MULTICAST OVERVIEW ...
Страница 604: ...604 CHAPTER 43 MLD SNOOPING CONFIGURATION ...
Страница 628: ...628 CHAPTER 46 IGMP CONFIGURATION ...
Страница 699: ...Troubleshooting MSDP 699 4 Verify that the C BSR address is different from the anycast RP address ...
Страница 700: ...700 CHAPTER 48 MSDP CONFIGURATION ...
Страница 812: ...812 CHAPTER 57 DHCP SERVER CONFIGURATION ...
Страница 822: ...822 CHAPTER 58 DHCP RELAY AGENT CONFIGURATION ...
Страница 834: ...834 CHAPTER 61 BOOTP CLIENT CONFIGURATION ...
Страница 850: ...850 CHAPTER 63 IPV4 ACL CONFIGURATION ...
Страница 856: ...856 CHAPTER 64 IPV6 ACL CONFIGURATION ...
Страница 860: ...860 CHAPTER 65 QOS OVERVIEW ...
Страница 868: ...868 CHAPTER 66 TRAFFIC CLASSIFICATION TP AND LR CONFIGURATION ...
Страница 888: ...888 CHAPTER 69 PRIORITY MAPPING ...
Страница 894: ...894 CHAPTER 71 TRAFFIC MIRRORING CONFIGURATION ...
Страница 904: ...904 CHAPTER 72 PORT MIRRORING CONFIGURATION ...
Страница 930: ...930 CHAPTER 74 UDP HELPER CONFIGURATION ...
Страница 990: ...990 CHAPTER 79 FILE SYSTEM MANAGEMENT CONFIGURATION ...
Страница 1000: ...1000 CHAPTER 80 FTP CONFIGURATION ...
Страница 1020: ...1020 CHAPTER 82 INFORMATION CENTER CONFIGURATION ...
Страница 1038: ...1038 CHAPTER 84 SYSTEM MAINTAINING AND DEBUGGING ...
Страница 1046: ...1046 CHAPTER 85 DEVICE MANAGEMENT ...
Страница 1129: ...SSH Client Configuration Examples 1129 SwitchB ...
Страница 1130: ...1130 CHAPTER 88 SSH CONFIGURATION ...
Страница 1160: ...1160 CHAPTER 90 RRPP CONFIGURATION ...
Страница 1180: ...1180 CHAPTER 91 PORT SECURITY CONFIGURATION ...
Страница 1192: ...1192 CHAPTER 92 LLDP CONFIGURATION ...
Страница 1202: ...1202 CHAPTER 93 POE CONFIGURATION ...
Страница 1218: ...1218 CHAPTER 96 HTTPS CONFIGURATION ...