1-17
z
Whether or not a user logs in through multiple network adapters (that is, when the user attempts to
log in, it contains more than one active network adapters.)
A switch can optionally take the following actions in response to any of the above three cases:
z
Only disconnects the user but sends no Trap packets, which can be achieved by using the
dot1x
supp-proxy-check logoff
command.
z
Sends Trap packets without disconnecting the user, which can be achieved by using the
dot1x
supp-proxy-check trap
command.
This function needs the cooperation of 802.1x clients and the CAMS server:
z
Multiple network adapter checking, proxy checking, and IE proxy checking are enabled on the
802.1x client.
z
The CAMS server is configured to disable the use of multiple network adapters, proxies, and IE
proxy.
By default, proxy checking is disabled on 802.1x client. In this case, if you configure the CAMS server to
disable the use of multiple network adapters, proxies, and IE proxy, it sends messages to the 802.1x
client to ask the latter to disable the use of multiple network adapters, proxies, and IE proxy after the
user passes the authentication.
z
The 802.1x proxy checking function needs the cooperation of H3C's 802.1x client program.
z
The proxy checking function takes effect only after the client version checking function is enabled
on the switch (using the
dot1x version-check
command).
Related commands:
display dot1x
.
Examples
# Configure to disconnect the users connected to Ethernet 1/0/1 through Ethernet 1/0/8 ports if they are
detected logging in through proxies.
<Sysname> system-view
System View: return to User View with Ctrl+Z.
[Sysname] dot1x supp-proxy-check logoff
[Sysname] dot1x supp-proxy-check logoff interface Ethernet 1/0/1 to Ethernet 1/0/8
# Configure the switch to send Trap packets if the users connected to Ethernet 1/0/9 port is detected
logging in through proxies.
[Sysname] dot1x supp-proxy-check trap
[Sysname] dot1x supp-proxy-check trap interface Ethernet 1/0/9
dot1x timer
Syntax
dot1x timer
{
handshake-period handshake-period-value
|
quiet-period quiet-period-value
|
server-timeout
server-timeout-value
|
supp-timeout
supp-timeout-value
|
tx-period tx-period-value
|
ver-period ver-period-value
}
Содержание 5500-EI PWR
Страница 43: ...2 6...
Страница 76: ...1 17...
Страница 228: ...ii stp transmit limit 1 44 vlan mapping modulo 1 45 vlan vpn tunnel 1 46...
Страница 477: ...5 24 Sysname vlan 2 Sysname vlan2 service type multicast...
Страница 503: ...2 3 System View return to User View with Ctrl Z Sysname dot1x url http 192 168 19 23...
Страница 519: ...iii...
Страница 597: ...2 2 security policy server 192 168 0 1 user name format without domain...
Страница 648: ...1 9 Examples Clear static ARP entries Sysname reset arp static...
Страница 663: ...4 3 Sysname resilient arp interface vlan interface 2...
Страница 767: ...1 28 From 12 00 Jan 1 2008 to 12 00 Jun 1 2008...
Страница 1111: ...ii xmodem get 3 18...
Страница 1314: ...A 44 Z...