91
Step Command Remarks
1.
Enter system view.
system-view
N/A
2.
Set the client timeout
timer.
dot1x timer supp-timeout
supp-timeout-value
The default is 30 seconds.
3.
Set the server
timeout timer.
dot1x timer server-timeout
server-timeout-value
The default is 100 seconds.
Configuring online user handshake
The online user handshake feature checks the connectivity status of online 802.1X users. The
access device sends handshake requests (EAP-Request/Identity) to online users at the interval
specified by the
dot1x timer handshake-period
command. If the device does not receive any
EAP-Response/Identity packets from an online user after it has made the maximum handshake
attempts, the device sets the user to offline state. To set the maximum handshake attempts, use the
dot1x retry
command.
Typically, the device does not reply to 802.1X clients' EAP-Response/Identity packets with
EAP-Success packets. Some 802.1X clients will go offline if they do not receive the EAP-Success
packets for handshake. To avoid this problem, enable the online user handshake reply feature.
If iNode clients are deployed, you can also enable the online user handshake security feature to
check authentication information in the handshake packets from clients. This feature can prevent
802.1X users that use illegal client software from bypassing iNode security check, such as dual
network interface cards (NICs) detection. If a user fails the handshake security checking, the device
sets the user to the offline state.
Configuration guidelines
When you configure online user handshake, follow these restrictions and guidelines:
•
To use the online user handshake security feature, make sure the online user handshake
feature is enabled.
•
The online user handshake security feature takes effect only on the network where the iNode
client and IMC server are used.
•
If the network has 802.1X clients that cannot exchange handshake packets with the access
device, disable the online user handshake feature. This operation prevents the 802.1X
connections from being incorrectly torn down.
•
Enable the online user handshake reply feature only if 802.1X clients will go offline without
receiving EAP-Success packets from the device.
Configuration procedure
To configure the online user handshake feature:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
(Optional.) Set the
handshake timer.
dot1x timer
handshake-period
handshake-period-value
The default is 15 seconds.
3.
Enter Ethernet interface
view.
interface
interface-type
interface-number
N/A
4.
Enable the online user
dot1x handshake
By default, the feature is enabled.
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...