317
Default
The authorization-fail-offline feature is disabled. The device does not log off users that fail
authorization.
Views
System view
Predefined user roles
network-admin
mdc-admin
Parameters
quiet-period
: Enables the quiet timer for 802.1X or MAC authentication users that are logged off by
the authorization-fail-offline feature. The device adds these users to the 802.1X or MAC
authentication quiet queue. Within the quiet timer, the device does not process packets from these
users or authenticate them. If you do not specify this keyword, the quiet timer feature is disabled for
users that are logged off by the authorization-fail-offline feature. The device immediately
authenticates these users upon receiving packets from them.
Usage guidelines
The authorization-fail-offline feature logs off port security users that fail ACL authorization.
A user fails ACL authorization in the following situations:
•
The device fails to authorize the specified ACL to the user.
•
The server assigns a nonexistent ACL to the user.
If this feature is disabled, the device does not log off users that fail ACL authorization. However, the
device outputs messages to report the failure.
For the
quiet-period
keyword to take effect, complete the following tasks:
•
For 802.1X users, use the
dot1x quiet-period
command to enable the quiet timer and use the
dot1x timer quiet-period
command to set the timer.
•
For MAC authentication users, use the
mac-authentication timer quiet
command to set the
quiet timer for MAC authentication.
Examples
# Enable the authorization-fail-offline feature.
<Sysname> system-view
[Sysname] port-security authorization-fail offline
Related commands
display port-security
dot1x
quiet-period
dot1x timer quiet-period
mac-authentication timer
port-security enable
Use
port-security enable
to enable port security.
Use
undo port-security enable
to disable port security.
Syntax
port-security enable
Содержание FlexNetwork 7500 Series
Страница 350: ...335 Related commands display port security port security enable ...
Страница 379: ...364 Sysname system view Sysname keychain abc mode absolute Sysname keychain abc tcp kind 252 ...
Страница 519: ...504 Related commands display ssh2 algorithm ssh2 algorithm cipher ssh2 algorithm key exchange ssh2 algorithm mac ...