225
Parameters
auth-delay
auth-delay-time
: Specifies the delay time for MAC authentication in seconds. The value
range is 1 to 180.
reauth-period
reauth-period-value
: Specifies the port-specific periodic MAC reauthentication timer
in seconds. The value range is 60 to 7200.
Usage guidelines
When both 802.1X authentication and MAC authentication are enabled on a port, you can delay
MAC authentication so that 802.1X authentication is preferentially triggered. If no 802.1X
authentication is triggered or if 802.1X authentication fails within the delay period, the port continues
to process MAC authentication.
Do not set the port security mode to
mac-else-userlogin-secure
or
mac-else-userlogin-secure-ext
when you want to use MAC authentication delay. The delay does
not take effect on a port in either of the two modes. For more information about port security modes,
see "Port security commands."
The device reauthenticates online MAC authentication users on a port at the specified periodic
reauthentication interval if the port is enabled with periodic MAC reauthentication. To enable periodic
MAC reauthentication on a port, use the
mac-authentication re-authenticate
command.
A change to the port-specific periodic reauthentication timer applies to online users only after the old
timer expires.
The device selects a periodic reauthentication timer for MAC reauthentication in the following order:
1.
Server-assigned reauthentication timer.
2.
Port-specific reauthentication timer.
3.
Global reauthentication timer.
4.
Default reauthentication timer.
Examples
# Enable MAC authentication delay on Ten-GigabitEthernet 1/0/1 and set the delay time to 10
seconds.
<Sysname> system-view
[Sysname] interface ten-gigabitethernet 1/0/1
[Sysname-Ten-GigabitEthernet1/0/1] mac-authentication timer auth-delay 10
Related commands
display mac-authentication
port-security port-mode
mac-authentication timer (system view)
Use
mac-authentication
timer
to configure a MAC authentication timer.
Use
undo mac-authentication
timer
to restore the default of a MAC authentication timer.
Syntax
mac-authentication
timer
{
offline-detect
offline-detect-value
|
quiet
quiet-value
|
reauth-period
reauth-period-value
|
server-timeout
server-timeout-value
}
undo mac-authentication
timer
{
offline-detect
|
quiet
|
reauth-period
|
server-timeout
}
Default
The following MAC authentication timers apply:
•
The offline detect timer is 300 seconds.
Содержание FlexNetwork 7500 Series
Страница 350: ...335 Related commands display port security port security enable ...
Страница 379: ...364 Sysname system view Sysname keychain abc mode absolute Sysname keychain abc tcp kind 252 ...
Страница 519: ...504 Related commands display ssh2 algorithm ssh2 algorithm cipher ssh2 algorithm key exchange ssh2 algorithm mac ...