93
the network through the port. The implementation of a mandatory authentication domain enhances
the flexibility of 802.1X access control deployment.
To specify a mandatory authentication domain for a port:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter Ethernet interface
view.
interface
interface-type
interface-number
N/A
3.
Specify a mandatory 802.1X
authentication domain on the
port.
dot1x mandatory-domain
domain-name
By default, no mandatory 802.1X
authentication domain is
specified.
Setting the quiet timer
The quiet timer enables the access device to wait a period of time before it can process any
authentication request from a client that has failed an 802.1X authentication.
You can edit the quiet timer, depending on the network conditions.
•
In a vulnerable network, set the quiet timer to a high value.
•
In a high-performance network with quick authentication response, set the quiet timer to a low
value.
To set the quiet timer:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enable the quiet timer.
dot1x quiet-period
By default, the timer is disabled.
3.
(Optional.) Set the quiet
timer.
dot1x timer quiet-period
quiet-period-value
The default is 60 seconds.
Configuring 802.1X reauthentication
Overview
802.1X reauthentication tracks the connection status of online users and updates the authorization
attributes assigned by the server. The attributes include the ACL and VLAN.
The following methods are available for 802.1X reauthentication:
•
Manual
reauthentication
—Allows you to manually reauthenticate all online 802.1X users on a
port.
•
Periodic
reauthentication
—Reauthenticates online users at a user-configurable
reauthentication interval.
By default, the device logs off online 802.1X users if no server is reachable for 802.1X
reauthentication. The keep-online feature keeps authenticated 802.1X users online when no server
is reachable for 802.1X reauthentication, either manually or periodically.
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...