Enabling/Disabling A Quiet-Period Timer; Client Version Checking Configuration; Enabling The 802.1X Client Version Checking Function; Configuring The Maximum Number Of Retires To Send Version Checking Request Packets - 3Com 5500-SI Configuration Manual

5500 series
Hide thumbs Also See for 5500-SI:
Table of Contents

Advertisement

Enabling/Disabling a
Quiet-Period Timer
802.1x Client Version
Checking
Configuration
Enabling the 802.1x
Client Version Checking
Function
Configuring the
Maximum Number of
Retires to Send Version
Checking Request
Packets
You can use the following commands to enable/disable a quiet-period timer of an
Authenticator (which can be a Switch 5500). If an 802.1x user has not passed the
authentication, the Authenticator will keep quiet for a while (which is specified by
dot1x timer quiet-period
During the quiet period, the Authenticator does not do anything related to 802.1x
authentication.
Perform the following configuration in System View.
Table 422 Enabling/Disabling a Quiet-Period Timer
Operation
Enable a quiet-period timer
Disable a quiet-period timer
By default, the quiet-period timer is disabled.
With the 802.1x client version checking function enabled on a switch, the switch
checks the version and validity of the 802.1x client running on supplicant systems to
prevent those that use earlier versions of 802.1x client or illegal clients from logging
in. The following are configurations concerning the 802.1x client version checking
function.

Enabling the 802.1x Client Version Checking Function

Configuring the Maximum Number of Retires to Send Version Checking Request
Packets
Configuring the Version Checking Timer
Table 423 Enable the 802.1x client version checking function
Operation
Command
Enter system view
system-view
Enable the 802.1x
dot1x version-check [ interface
client version checking
interface-list ]
function
As for the dot1x version-check command, if you execute it in system view without
specifying the interface-list argument, the command applies to all ports. Otherwise,
the command applies to the specified ports.
You can also execute the dot1x version-check command in Ethernet port view. In
this case, the interface-list argument is unnecessary and the command applies to the
current port only.
After sending a version request packet to a supplicant system, a switch sends another
one to the supplicant system if it does not receive the response from the supplicant
system for the period set by the version checking timer. It continues to send version
request packets to the supplicant system if it still does not receive the response from
802.1x Client Version Checking Configuration 399
command) before launching the authentication again.
Command
dot1x quiet-period
undo dot1x quiet-period
Description
Required
By default, 802.1x client version
checking is disabled.

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

5500-ei5500g-ei

Table of Contents