Configuring The Online User Handshake Feature; Configuration Guidelines; Configuration Procedure; Configuring The Authentication Trigger Feature - HP FlexFabric 5700 Series Security Configuration Manual

Hide thumbs Also See for FlexFabric 5700 Series:
Table of Contents

Advertisement

Configuring the online user handshake feature

The online user handshake feature checks the connectivity status of online 802.1X users. The access
device sends handshake messages to online users at the interval specified by the dot1x timer
handshake-period command. If the device does not receive any responses from an online user after it
has made the maximum handshake attempts, the device sets the user to offline state. To set the maximum
handshake attempts, use the dot1x retry command.
If iNode clients are deployed, you can also enable the online user handshake security feature to check
authentication information in the handshake packets from clients. This feature can prevent 802.1X users
who use illegal client software from bypassing iNode security check, such as dual network interface
cards (NICs) detection. If a user fails the handshake security checking, the device sets the user to the
offline state.

Configuration guidelines

When you configure the online user handshake feature, follow these restrictions and guidelines:
To use the online user handshake security feature, make sure the online user handshake feature is
enabled.
The online user handshake security feature takes effect only on the network where the iNode client
and IMC server are used.
If the network has 802.1X clients that cannot exchange handshake packets with the access device,
disable the online user handshake feature. This operation prevents the 802.1X connections from
being incorrectly torn down.

Configuration procedure

To configure the online user handshake feature:
Step
1.
Enter system view.
2.
(Optional.) Set the handshake
timer.
3.
Enter Layer 2 Ethernet
interface view.
Enable the online handshake
4.
feature.
5.
(Optional.) Enable the online
user handshake security
feature.

Configuring the authentication trigger feature

The authentication trigger feature enables the access device to initiate 802.1X authentication when
802.1X clients cannot initiate authentication.
Command
system-view
dot1x timer handshake-period
handshake-period-value
interface interface-type
interface-number
dot1x handshake
dot1x handshake secure
83
Remarks
N/A
The default is 15 seconds.
N/A
By default, the feature is enabled.
By default, the feature is disabled.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents