Enabling The Periodic Online User Re-Authentication Function; Configuring An 802.1X Guest Vlan - HP 12500 Series Configuration Manual

Routing
Table of Contents

Advertisement

Enabling the periodic online user re-authentication
function
Periodic online user re-authentication tracks the connection status of online users and updates the
authorization attributes assigned by the server, such as the ACL. The re-authentication interval is user
configurable.
To enable the periodic online user re-authentication function:
Step
1.
Enter system view.
2.
Set the periodic
re-authentication timer.
3.
Enter Ethernet interface view.
4.
Enable periodic online user
re-authentication.
The periodic online user re-authentication timer can also be set by the authentication server in the
session-timeout attribute. The server-assigned timer overrides the timer setting on the access device, and
enables periodic online user re-authentication, even if the function is not configured. Support for the
server assignment of re-authentication timer and the re-authentication timer configuration on the server
vary with servers.
The VLAN assignment status must be consistent before and after re-authentication. If the authentication
server has assigned a VLAN before re-authentication, it must also assign a VLAN at re-authentication. If
the authentication server has assigned no VLAN before re-authentication, it must not assign one at
re-authentication. Violation of either rule can cause the user to be logged off. The VLANs assigned to an
online user before and after re-authentication can be the same or different.

Configuring an 802.1X guest VLAN

Follow these guidelines when you configure an 802.1X guest VLAN:
You can configure only one 802.1X guest VLAN on a port. The 802.1X guest VLANs on different
ports can be different.
Assign different IDs to the PVID and the 802.1X guest VLAN on a port, so the port can correctly
process incoming VLAN tagged traffic.
With 802.1X authentication, a hybrid port is always assigned to a VLAN as an untagged member.
After the assignment, do not re-configure the port as a tagged member in the VLAN.
Use
Table 6
Table 6 Relationships of the 802.1X guest VLAN and other security features
Feature
Super VLAN
Command
system-view
dot1x timer reauth-period
reauth-period-value
interface interface-type
interface-number
dot1x re-authenticate
when configuring multiple security features on a port.
Relationship description
You cannot specify a VLAN as both a super
VLAN and an 802.1X guest VLAN.
86
Remarks
N/A
Optional.
The default is 3600 seconds.
N/A
By default, the function is disabled.
Reference
See "Super VLAN
configuration."

Advertisement

Table of Contents
loading

Table of Contents