
C
HAPTER
16
| IEEE 802.1X Commands
– 273 –
D
EFAULT
S
ETTING
Allows all new clients.
C
OMMAND
U
SAGE
The switch has a fixed pool of state-machines, from which all ports draw
whenever a new client is seen on the port. When a given port's maximum
is reached (counting both authorized and unauthorized clients), further
new clients are disallowed access. Since all ports draw from the same pool,
it may happen that a configured maximum cannot be granted, if the
remaining ports have already used all available state-machines.
E
XAMPLE
Dot1x>clients 9 10
Dot1x>
dot1x agetime
This command displays or sets the time between checking for activity on
successfully authenticated MAC addresses.
S
YNTAX
dot1x agetime
[
age-time
]
age-time
- The period used to calculate when to age out a client
allowed access to the switch through MAC-based authentication as
described below. (Range: 10-1000000 seconds)
D
EFAULT
S
ETTING
300 seconds
C
OMMAND
U
SAGE
Suppose a client is connected to a 3rd party switch or hub, which in turn is
connected to a port on this switch that is running MAC-based
authentication, and suppose the client gets successfully authenticated.
Now assume that the client powers down his PC. What should make the
switch forget about the authenticated client? Reauthentication will not
solve this problem, since this doesn't require the client to be present, as
discussed under Reauthentication Enabled above. The solution is aging out
authenticated clients.
A timer is started when the client gets authenticated. After half the age
period, the switch starts looking for frames sent by the client. If another
half age period elapses and no frames are seen, the client is considered
removed from the system, and it will have to authenticate again the next
time a frame is seen from it. If, on the other hand, the client transmits a
frame before the second half of the age period expires, the switch will
consider the client alive, and leave it authenticated. Therefore, an age
period of T will require the client to send frames more frequent than T/2 to
stay authenticated.
Содержание ES4528V-38
Страница 1: ...Management Guide www edge core com 28 Port Gigabit Ethernet Switch...
Страница 2: ......
Страница 4: ......
Страница 6: ...ABOUT THIS GUIDE 6...
Страница 22: ...FIGURES 22...
Страница 26: ...SECTION Getting Started 26...
Страница 46: ...CHAPTER 2 Initial Switch Configuration Managing System Files 46...
Страница 48: ...SECTION Web Configuration 48...
Страница 75: ...CHAPTER 4 Configuring the Switch Creating Trunk Groups 75 Figure 11 LACP Port Configuration...
Страница 135: ...CHAPTER 4 Configuring the Switch Simple Network Management Protocol 135 Figure 34 SNMP System Configuration...
Страница 186: ...CHAPTER 6 Performing Basic Diagnostics Running Cable Diagnostics 186...
Страница 191: ...CHAPTER 7 Performing System Maintenance Managing Configuration Files 191 Figure 72 Configuration Upload...
Страница 192: ...CHAPTER 7 Performing System Maintenance Managing Configuration Files 192...
Страница 242: ...CHAPTER 12 Port Commands 242...
Страница 248: ...CHAPTER 13 Link Aggregation Commands 248...
Страница 266: ...CHAPTER 15 RSTP Commands 266...
Страница 276: ...CHAPTER 16 IEEE 802 1X Commands 276...
Страница 286: ...CHAPTER 17 IGMP Commands 286...
Страница 294: ...CHAPTER 18 LLDP Commands 294...
Страница 300: ...CHAPTER 19 MAC Commands 300...
Страница 310: ...CHAPTER 21 PVLAN Commands 310...
Страница 322: ...CHAPTER 22 QoS Commands 322...
Страница 356: ...CHAPTER 26 SNMP Commands 356...
Страница 359: ...CHAPTER 27 HTTPS Commands 359 EXAMPLE HTTPS redirect enable HTTPS...
Страница 360: ...CHAPTER 27 HTTPS Commands 360...
Страница 366: ...CHAPTER 29 UPnP Commands 366...
Страница 374: ...CHAPTER 31 Firmware Commands 374...
Страница 376: ...SECTION Appendices 376...
Страница 390: ...GLOSSARY 390...
Страница 394: ...INDEX 394 W web interface access requirements 49 configuration buttons 50 home page 50 menu list 51 panel display 51...
Страница 395: ......
Страница 396: ...ES4528V E072009 ST R01 149100000014A...