1-13
To do…
Use the command…
Remarks
Set the maximum number of
attempts to send an
authentication request to a
client
dot1x retry
max-retry-value
Optional
2 by default
Set timers
dot1x timer
{
handshake-period
handshake-period-value
|
quiet-period
quiet-period-value
|
server-timeout
server-timeout-value
|
supp-timeout
supp-timeout-value
|
tx-period
tx-period-value
}
Optional
The defaults are as follows:
15 seconds for the handshake
timer,
60 seconds for the quiet timer,
100 seconds for the server
timeout timer,
30 seconds for the client
timeout timer, and
30 seconds for the username
request timeout timer.
Enable the quiet timer
dot1x quiet-period
Optional
Disabled by default
Note that:
z
For 802.1X to take effect on a port, you must enable it both globally in system view and for the port
in system view or Ethernet interface view.
z
You can also enable 802.1X and set port access control parameters (that is, the port access control
mode, port access method, and the maximum number of users) for a port in Ethernet interface view.
For detailed configuration, refer to
Configuring 802.1X for a Port
. The only difference between
configuring 802.1X globally and configuring 802.1X for a port lies in the applicable scope. If both a
global setting and a local setting exist for an argument of a port, the last configured one is in effect.
z
802.1X timers only need to be changed in special or extreme network environments. For example,
you can give the client timeout timer a higher value in a low-performance network, give the quiet
timer a higher value in a vulnerable network or a lower value for quicker authentication response, or
adjust the server timeout timer to suit the performance of the authentication server.
Configuring 802.1X for a Port
Enabling 802.1X for a port
Follow these steps to enable 802.1X for a port:
To do…
Use the command…
Remarks
Enter system view
system-view
—
In system view
dot1x
interface
interface-list
interface
interface-type
interface-number
Enable
802.1X for
one or more
ports
In Ethernet
interface view
dot1x
Required
Use either approach.
Disabled by default
Configuring 802.1X parameters for a port
Follow these steps to configure 802.1X parameters for a port:
Содержание 4500G PWR 24-Port
Страница 200: ...1 5 ProviderB GigabitEthernet1 0 2 undo stp enable ProviderB GigabitEthernet1 0 2 bpdu tunnel dot1q stp ...
Страница 252: ...1 7 Clearing ARP entries from the ARP table may cause communication failures ...
Страница 362: ...i Table of Contents 1 Dual Stack Configuration 1 1 Dual Stack Overview 1 1 Configuring Dual Stack 1 1 ...
Страница 407: ...1 8 1 1 ms 1 ms 1 ms 1 1 6 1 2 1 ms 1 ms 1 ms 1 1 4 1 3 1 ms 1 ms 1 ms 1 1 2 2 Trace complete ...
Страница 786: ...1 16 3 In the case of PIM SM use the display current configuration command to check the BSR and RP information ...
Страница 1387: ...1 23 ...
Страница 1443: ...i Table of Contents 1 URPF Configuration 1 1 URPF Overview 1 1 What is URPF 1 1 How URPF Works 1 1 Configuring URPF 1 2 ...
Страница 1720: ...ii Single Device Upgrade 3 4 IRF System Upgrade 3 5 ...