Configuration Procedure; Configuring The Authentication Trigger Feature; Configuration Guidelines - HPE Moonshot 45Gc Security Configuration Manual

Switch module
Table of Contents

Advertisement

If the network has 802.1X clients that cannot exchange handshake packets with the access
device, disable the online user handshake feature. This operation prevents the 802.1X
connections from being incorrectly torn down.
Enable the online user handshake reply feature only if 802.1X clients will go offline without
receiving EAP-Success packets from the device.

Configuration procedure

To configure the online user handshake feature:
Step
1.
Enter system view.
2.
(Optional.) Set the
handshake timer.
3.
Enter Layer 2 Ethernet
interface view.
4.
Enable the online handshake
feature.
5.
(Optional.) Enable the online
user handshake security
feature.
6.
(Optional.) Enable the
802.1X online user
handshake reply feature.

Configuring the authentication trigger feature

The authentication trigger feature enables the access device to initiate 802.1X authentication when
802.1X clients cannot initiate authentication.
This feature provides the multicast trigger and unicast trigger (see 802.1X authentication initiation in
"802.1X
overview").

Configuration guidelines

When you configure the authentication trigger feature, follow these guidelines:
Enable the multicast trigger on a port when the clients attached to the port cannot send
EAPOL-Start packets to initiate 802.1X authentication.
Enable the unicast trigger on a port if only a few 802.1X clients are attached to the port and
these clients cannot initiate authentication.
To avoid duplicate authentication packets, do not enable both triggers on a port.
Configuration procedure
To configure the authentication trigger feature on a port:
Step
1.
Enter system view.
Command
system-view
dot1x timer handshake-period
handshake-period-value
interface interface-type
interface-number
dot1x handshake
dot1x handshake secure
dot1x handshake reply enable
Command
system-view
84
Remarks
N/A
The default is 15 seconds.
N/A
By default, the feature is enabled.
By default, the feature is disabled.
By default, the device does not
reply to 802.1X clients'
EAP-Response/Identity packets
during the online handshake
process.
Remarks
N/A

Advertisement

Table of Contents
loading

Table of Contents