XS26GS Managed Optical Ethernet Switch User Manual
26
the switch does not perform any 802.1x authentication-related actions for the supplicant
system. The value is in the range of 1 to 65535, and is set to 60 seconds by default.
Tx Period
: sets the transmission timer. This timer sets the tx-period and is triggered in
two cases. The first case is when the client requests authentication. The switch sends a
unicast request/identity packet to a supplicant system and then triggers the
transmission timer. The switch sends another request/identity packet to the supplicant
system if it does not receive the reply packet from the supplicant system when this timer
times out. The second case is when the switch authenticates the 802.1x client which
cannot request for authentication actively. The switch sends multicast request/identity
packets periodically through the port enabled with 802.1x function. In this case, this
timer sets the interval to send the multicast request/identity packets. It is in the range
of 1 to 65535; the default value is 30 seconds.
Supplicant Timeout
: sets the supplicant system timer. This timer sets the
supp-timeout period and is triggered by the switch after the switch sends a
request/challenge packet to a supplicant system. The switch sends another
request/challenge packet to the supplicant system if the switch does not receive any
response from the supplicant system when this timer times out. It is in the range of 1 to
300; the default value is 30 seconds.
Server Timeout
: sets the radius server timer. This timer sets the server-timeout period.
After sending an authentication request packet to the radius server, a switch sends
another authentication request packet if it does not receive any response from the radius
server when this timer times out. It is in the range of 1 to 300; the default value is 30
seconds.
Max Request Count
: sets the maximum number of times that a switch sends
authentication request packets to a user. It is in the range of 1 to 10, and the default
value is 2.
Reauth Period
: sets re-authentication interval in seconds. After this timer expires, the
switch indicates 802.1x re-authentication. It is in the range of 60 to 7200; the default
value is 3600 seconds.
Guest VLAN
: can choose a guest VLAN on the switch to provide limited services to
clients, such as downloading. These clients might be upgraded for IEEE 802.1x
authentication.
When enabling a guest VLAN on an IEEE 802.1x port, the switch assigns the client
port to a guest VLAN in case that the switch does not receive any response to its EAP
request/identity frame, or EAPOL packets are not sent by the client. The switch allows
the client that is failed in authentication to access the guest VLAN, regardless of whether
EAPOL packets have been detected. However, access to external ports out of guest VLAN
still needs to be authorized.