92
Step Command
Remarks
handshake feature.
5.
(Optional.) Enable the online
user handshake security
feature.
dot1x handshake secure
By default, the feature is disabled.
6.
(Optional.) Enable the
802.1X online user
handshake reply feature.
dot1x handshake reply enable
By default, the device does not
reply to 802.1X clients'
EAP-Response/Identity packets
during the online handshake
process.
Configuring the authentication trigger feature
The authentication trigger feature enables the access device to initiate 802.1X authentication when
802.1X clients cannot initiate authentication.
This feature provides the multicast trigger and unicast trigger (see 802.1X authentication initiation in
"
").
Configuration guidelines
When you configure the authentication trigger feature, follow these guidelines:
•
Enable the multicast trigger on a port when the clients attached to the port cannot send
EAPOL-Start packets to initiate 802.1X authentication.
•
Enable the unicast trigger on a port if only a few 802.1X clients are attached to the port and
these clients cannot initiate authentication.
•
To avoid duplicate authentication packets, do not enable both triggers on a port.
Configuration procedure
To configure the authentication trigger feature on a port:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
(Optional.) Set the username
request timeout timer.
dot1x timer tx-period
tx-period-value
The default is 30 seconds.
3.
Enter Ethernet interface
view.
interface
interface-type
interface-number
N/A
4.
Enable an authentication
trigger.
dot1x
{
multicast-trigger
|
unicast-trigger
}
By default, the multicast trigger is
enabled, and the unicast trigger is
disabled.
Specifying a mandatory authentication domain on
a port
You can place all 802.1X users in a mandatory authentication domain for authentication,
authorization, and accounting on a port. No user can use an account in any other domain to access
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...