Optional) Configuring The Quiet Timer Function - Huawei Quidway S3700 Series Configuration Manual

Hide thumbs Also See for Quidway S3700 Series:
Table of Contents

Advertisement

Quidway S3700 Series Ethernet Switches
Configuration Guide - Security
Step 2 Run:
dot1x timer { client-timeout client-timeout-value | handshake-period handshake-
period-value | quiet-period quiet-period-value | reauthenticate-period
reauthenticate-period-value | server-timeout server-timeout-value | tx-period tx-
period-value }
The timers of 802.1x authentication are set.
l client-timeout: Authentication timeout timer of the client. By default, the timeout timer is
l handshake-period: Interval of handshake packets from the S3700 to the 802.1X client. By
l quiet-period: Period of the quiet timer. By default, the quiet timer is 60s.
l reauthenticate-period: Re-authentication interval. By default, the re-authentication interval
l server-timeout: Timeout timer of the authentication server. By default, the timeout timer of
l tx-period: Interval for sending authentication requests. By default, the interval for sending
The dot1x timer command only sets the values of the timers, and you need to enable the
corresponding timers by running commands or adopting the default settings.
----End

2.4.11 (Optional) Configuring the Quiet Timer Function

Context
If a user fails to pass 802.1x authentication after the quiet timer function is enabled, the S3700
considers the user as quiet for a period and does not process authentication requests from the
user in this period. In this manner, the impact caused by frequent authentication is prevented.
In the case that the quiet timer function is enabled, to prevent the 802.1x user from entering the
silent state after the first authentication failure, you can set the number of authentication failures
before the 802.1x user enters the silent state to be greater than 1 on the S3700.
Procedure
Step 1 Run:
system-view
The system view is displayed.
Step 2 Run:
dot1x quiet-period
The quiet timer function is enabled.
By default, the quiet timer function is disabled.
During the quite period, the S3700 discards the 802.1x authentication request packets from the
user. You can run the dot1x timer command to set the quiet period. For details, see
(Optional) Configuring 802.1x
Issue 01 (2011-07-15)
30s.
default, the handshake interval is 15s.
is 3600s.
the authentication server is 30s.
the authentication request packets is 30s.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
Timers.
2 NAC Configuration
2.4.10
63

Advertisement

Table of Contents
loading

Table of Contents