Configuration Guidelines; Configuration Procedure; Configuring The Authentication Trigger Feature - HP FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Configuration guidelines

When you configure the online user handshake feature, follow these restrictions and guidelines:
The SmartOn feature and the online user handshake feature are mutually exclusive. Before you
enable the online user handshake feature, make sure the SmartOn feature is disabled.
To use the online user handshake security feature, make sure the online user handshake
feature is enabled.
The online user handshake security feature takes effect only on the network where the iNode
client and IMC server are used.
If the network has 802.1X clients that cannot exchange handshake packets with the access
device, disable the online user handshake feature. This operation prevents the 802.1X
connections from being incorrectly torn down.
Enable the online user handshake reply feature only if 802.1X clients will go offline without
receiving EAP-Success packets from the device.

Configuration procedure

To configure the online user handshake feature:
Step
1.
Enter system view.
2.
(Optional.) Set the
handshake timer.
3.
Enter Layer 2 Ethernet
interface view.
4.
Enable the online user
handshake feature.
5.
(Optional.) Enable the online
user handshake security
feature.
6.
(Optional.) Enable the
802.1X online user
handshake reply feature.

Configuring the authentication trigger feature

The authentication trigger feature enables the access device to initiate 802.1X authentication when
802.1X clients cannot initiate authentication.
This feature provides the multicast trigger and unicast trigger (see 802.1X authentication initiation in
"802.1X overview").
Configuration guidelines
When you configure the authentication trigger feature, follow these guidelines:
Enable the multicast trigger on a port when the clients attached to the port cannot send
EAPOL-Start packets to initiate 802.1X authentication.
Command
system-view
dot1x timer handshake-period
handshake-period-value
interface interface-type
interface-number
dot1x handshake
dot1x handshake secure
dot1x handshake reply enable
89
Remarks
N/A
The default is 15 seconds.
N/A
By default, the feature is enabled.
By default, the feature is disabled.
By default, the device does not
reply to 802.1X clients'
EAP-Response/Identity packets
during the online handshake
process.

Advertisement

Table of Contents
loading

Table of Contents