Enabling The Online User Handshake Function - H3C S5120-SI Series Operation Manual

Hide thumbs Also See for S5120-SI Series:
Table of Contents

Advertisement

To do...
Enter system view
Enter Ethernet interface view
Specify the port authorization
mode for the port
Specify the port access control
method for the port
Set the maximum number of
users for the port
Note that:
Enabling 802.1X on a port is mutually exclusive with adding the port to an aggregation group.
For a user-side device sending untagged traffic, the voice VLAN function and 802.1X are mutually
exclusive and cannot be configured together on the same port. For details about voice VLAN, refer
to VLAN Configuration.
In EAP relay authentication mode, the device encapsulates the 802.1X user information in the EAP
attributes of RADIUS packets and sends the packets to the RADIUS server for authentication. In
this case, you can configure the user-name-format command but it does not take effect. For
information about the user-name-format command, refer to AAA Commands.
If the username of a client contains the version number or one or more blank spaces, you can
neither retrieve information nor disconnect the client by using the username. However, you can use
items such as IP address and connection index number to do so.

Enabling the Online User Handshake Function

The online user handshake function allows the device to send handshake messages to online users to
check whether the users are still online at the interval specified by the dot1x timer handshake-period
command. If the device does not receive any response from an online user after the device has sent the
handshake packet for the maximum number of times, which is set by the dot1x retry command, the
device will set the user state to offline.
Follow these steps to configure the online user handshake function:
To do...
Enter system view
Enter Ethernet interface view
Enable the online handshake
function
Use the command...
system-view
interface interface-type
interface-number
dot1x port-control
{ authorized-force | auto |
unauthorized-force }
dot1x port-method
{ macbased | portbased }
dot1x max-user user-number
Use the command...
system-view
interface interface-type
interface-number
dot1x handshake
1-15
Remarks
Optional
auto by default
Optional
macbased by default
Optional
256 by default
Remarks
Optional
Enabled by default

Advertisement

Table of Contents
loading

Table of Contents