Enabling The Periodic Online User Reauthentication Feature; Displaying And Maintaining 802.1X; 802.1X Authentication Configuration Example; Network Requirements - HP 5920 Series Configuration Manual

Hide thumbs Also See for 5920 Series:
Table of Contents

Advertisement

Enabling the periodic online user reauthentication
feature
Periodic online user reauthentication tracks the connection status of online users, and updates the
authorization attributes assigned by the server. The reauthentication interval is user configurable.
The periodic online user reauthentication timer can also be set by the authentication server in the
session-timeout attribute. The server-assigned timer overrides the timer setting on the access device, and
enables periodic online user reauthentication, even if the feature is not configured. Support for the server
assignment of reauthentication timer and the reauthentication timer configuration on the server vary with
servers.
To enable the periodic online user reauthentication feature:
Step
1.
Enter system view.
2.
(Optional.) Set the periodic
reauthentication timer.
3.
Enter Layer 2 Ethernet
interface view.
4.
Enable periodic online user
reauthentication.

Displaying and maintaining 802.1X

Execute the display commands in any view and reset commands in user view.
Task
Display 802.1X session information, statistics,
or configuration information of specified or all
ports.
Clear 802.1X statistics.

802.1X authentication configuration example

Network requirements

As shown in
Ten-GigabitEthernet 1/0/1. Implement MAC-based access control on the port, so the logoff of one user
does not affect other online 802.1X users.
Use RADIUS servers to perform authentication, authorization, and accounting for the 802.1X users. If
RADIUS authentication fails, perform local authentication on the access device.
Figure
31, the access device performs 802.1X authentication for users that connect to port
Command
system-view
dot1x timer reauth-period
reauth-period-value
interface interface-type
interface-number
dot1x re-authenticate
Command
display dot1x [ sessions | statistics ] [ interface interface-type
interface-number ]
reset dot1x statistics [ interface interface-type
interface-number ]
76
Remarks
N/A
The default is 3600 seconds.
N/A
By default, the feature is disabled.

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

5900 series

Table of Contents