Setting 802.1X Re-Authentication - Huawei Quidway S3500 Series Operation Manual

Hide thumbs Also See for Quidway S3500 Series:
Table of Contents

Advertisement

Operation Manual - Security
Quidway S3500 Series Ethernet Switches
ports into Guest VLAN. After that, no 802.1x authentication is performed when the user
of the Guest VLAN visits the resources within this Guest VLAN. However, if the user
visits the outer resources, authentication is still needed. In this way, the requirements of
allowing unauthenticated users to access some resources are met, such as, the user
accesses some resources without installing 802.1x client, or the user upgrades 802.1x
client without authentication, and so on.
Perform the following configuration in system view or Ethernet port view.
Table 1-8 Enabling/disabling Guest VLAN
Operation
Enabling Guest VLAN
Disabling Guest VLAN
Note the following:
Guest VLAN is only supported in the port-based authentication mode.
A switch only can be configured with one Guest VLAN.
Users who skip the authentication, fail in the authentication or get offline belong to
the Guest VLAN.
Among S3500 series ethernet switches, S3552G, S3552P, S3528G, S3528P,
S3526E, S3526E FM, S3526E FS and S3526C support Guest VLAN, and S3526,
S3526 FM and S3526 FS don't.
If dot1x dhcp-launch is configured on the switch, the Guest VLAN function cannot be
implemented because the switch does not send active authentication packet in this
mode.

1.2.9 Setting 802.1x Re-authentication

Note:
Among S3500 series ethernet switches, S3552G, S3552P, S3528G, S3528P, S3526E
FM, S3526E FS and S3526C support this function, and S3526, S3526 FM and S3526
FS don't.
If the termination-action attribute on the RADIUS server is set to 1, the server then sets
the termination-action attribute in the access-accept packet which is sent to the switch
to 1. The switch re-authenticates the access user periodically after receiving this kind of
packets.
You can also enable 802.1x re-authentication on the switch through this configuration,
making the switch re-authenticates the access users periodically.
dot1x guest-vlan vlan-id [ interface interface-list ]
undo dot1x guest-vlan vlan-id [ interface interface-list ]
Huawei Technologies Proprietary
1-8
Chapter 1 802.1x Configuration
Command

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents