Configuration Guidelines; Configuration Procedure; Enabling The Proxy Detection Function - HPE FlexNetwork MSR Series Comware 5 Security Configuration Manual

Table of Contents

Advertisement

information in client handshake messages. If a user fails the authentication, the network access
device logs the user off.

Configuration guidelines

Follow these guidelines when you configure the online user handshake function:
To use the online handshake security function, make sure the online user handshake function is
enabled. Hewlett Packard Enterprise recommends that you use the iNode client software and
iMC server to ensure the normal operation of the online user handshake security function.
If the network has 802.1X clients that cannot exchange handshake packets with the network
access device, disable the online user handshake function to prevent their connections from
being inappropriately torn down.
You must disable proxy detection before disabling the online user handshake function.

Configuration procedure

To configure the online user handshake function:
Step
1.
Enter system view.
2.
Set the handshake timer.
3.
Enter Ethernet interface
view.
4.
Enable the online
handshake function.
5.
Enable the online
handshake security function.

Enabling the proxy detection function

The proxy detection function prevents users from using an authenticated 802.1X client as a network
access proxy to bypass monitoring and accounting. When a user is detected accessing the network
through a proxy, the network access device can send traps to the network management system or
log the user off by sending an offline message.
Before you enable the proxy detection function, complete the following tasks:
Enable the online user handshake function (see
function").
Deploy HPE iNode client software in your network.
To configure the proxy detection function:
Step
1.
Enter system view.
2.
Enable the proxy detection
function globally.
Command
system-view
dot1x timer handshake-period
handshake-period-value
interface interface-type
interface-number
dot1x handshake
dot1x handshake secure
"Configuring the online user handshake
Command
system-view
dot1x supp-proxy-check { logoff | trap }
94
Remarks
N/A
Optional.
The default is 15 seconds.
N/A
Optional.
By default, the function is
enabled.
Optional.
By default, the function is
disabled.
Remarks
N/A
By default, the
function is disabled.

Advertisement

Table of Contents
loading

Table of Contents