90
Enabling the periodic online user re-authentication function
Periodic online user re-authentication tracks the connection status of online users and updates the
authorization attributes assigned by the server, such as the ACL, VLAN, and user profile-based QoS. Use
dot1x timer reauth-period
to configure the interval for re-authentication.
To enable the periodic online user re-authentication function:
To do…
Command…
Remarks
1.
Enter system view.
system-view
—
2.
Enter Ethernet interface view.
interface
interface-type interface-
number
—
3.
Enable periodic online user re-
authentication.
dot1x re-authenticate
Required
Disabled by default
The periodic online user re-authentication timer can also be set by the authentication server in the
session-timeout attribute. The server-assigned timer overrides the timer setting on the access device and
enables periodic online user re-authentication, even if the function is not configured. Support for the
server assignment of a re-authentication timer and the re-authentication timer configuration on the server
vary with servers.
NOTE:
If the server assigns a VLAN before re-authentication and no VLAN after re-authentication, or vice
versa, the user is logged off and cannot access any network resource. VLANs assigned to the same
user before and after re-authentication can be different.
Configuring an 802.1X guest VLAN
Configuration guidelines
Follow these guidelines when you configure an 802.1X guest VLAN:
•
Configure only one 802.1X guest VLAN on a port. The 802.1X guest VLANs on different ports can
be different.
•
Assign different IDs for the voice VLAN, default VLAN, and 802.1X guest VLAN on a port, so that
the port can correctly process incoming VLAN tagged traffic.
•
With 802.1X authentication, a hybrid port is always assigned to a VLAN as an untagged member.
After the assignment, do not re-configure the port as a tagged member in the VLAN.
•
You cannot specify a VLAN as both a super VLAN and an 802.1X guest VLAN. For more
information, see
Layer 2
—
LAN Switching Configuration Guide.
Configuration prerequisites
•
Create the VLAN to be specified as the 802.1X guest VLAN.
•
On the 802.1X-enabled port that performs port-based access control, enable 802.1X multicast
trigger.