D-Link DWS-1008 User Manual page 289

Wireless 8 port switch with poe
Hide thumbs Also See for DWS-1008:
Table of Contents

Advertisement

DWS-1008 User's Manual
If a Bonded Auth user's session is ended due to 802.1X reauthentication or the RADIUS
Session-Timeout parameter, MSS can allow time for the user to reauthenticate. The amount
of time that MSS allows for reauthentication is controlled by the Bonded Auth period.
If the user does not reauthenticate within the Bonded Auth period, MSS deletes the information
about the machine session. After the machine session information is deleted, the Bonded
Auth user cannot reauthenticate. When this occurs, the user will need to log off, then log back
on, to access the network. After multiple failed reauthentication attempts, the user might need
to reboot the PC before logging on.
By default, the Bonded Auth period is 0 seconds. MSS does not wait for a Bonded Auth user
to reauthenticate.
You can set the Bonded Auth period to a value up to 300 seconds. D-Link recommends that
you try 60 seconds, and change the period to a longer value only if clients are unable to
authenticate within 60 seconds.
To set the Bonded Auth period, use the following command:
set dot1x bonded-period seconds
To reset the Bonded Auth period to its default value (0), use the following command:
clear dot1x bonded-period
Bonded Auth Configuration Example
To configure Bonded Auth:
• Configure separate authentication rules for the machine and for the user(s).
• Set the Bonded Auth period.
• Verify the configuration changes.
The following commands configure two 802.1X authentication rules for access to SSID
mycorp. The first rule is for authentication of all trusted laptop PCs at mycorp.com (host/*-
laptop.mycorp.com). The second rule is for bonded authentication of all users at mycorp.
com (*.mycorp.com). Both rules use pass-through as the protocol, and use RADIUS server
group radgrp1.
DWS-1008# set authentication dot1x ssid mycorp host/*-laptop.mycorp.com pass-through
radgrp1
success: change accepted.
DWS-1008# set authentication dot1x ssid mycorp *.mycorp.com bonded pass-through
radgrp1
success: change accepted.
D-Link Systems, Inc.
Configuring AAA for Network Users
284

Advertisement

Table of Contents
loading

Table of Contents