Enabling The Periodic Online User Reauthentication Feature; Configuring An 802.1X Guest Vlan; Configuration Guidelines - HPE Moonshot 45Gc Security Configuration Manual

Switch module
Table of Contents

Advertisement

Enabling the periodic online user reauthentication
feature
Periodic online user reauthentication tracks the connection status of online users, and updates the
authorization attributes assigned by the server. The attributes include the ACL, VLAN, and user
profile-based QoS. The reauthentication interval is user configurable.
The server-assigned RADIUS Session-Timeout (attribute 27) and Termination-Action (attribute 29)
attributes can affect the periodic online user reauthentication feature. To display the server-assigned
Session-Timeout and Termination-Action attributes, use the display dot1x connection command
(see Security Command Reference).
If the termination action is logging off users, periodic reauthentication takes effect only when the
periodic reauthentication timer is shorter than the session timeout timer. If the session timeout
timer is shorter, the device logs off online authenticated users when the session timeout timer
expires.
If the termination action is reauthenticating users, the periodic online user reauthentication
configuration on the device cannot take effect. The device reauthenticates online 802.1X users
after the session timeout timer expires.
Support for the server configuration and assignment of session timeout timer and termination action
depends on the server model.
If no server is reachable for 802.1X reauthentication, the device logs off the user or keeps it online,
depending on the configuration on the device.
The VLANs assigned to an online user before and after reauthentication can be the same or
different.
To enable the periodic online user reauthentication feature:
Step
1.
Enter system view.
2.
(Optional.) Set the periodic
reauthentication timer.
3.
Enter Layer 2 Ethernet
interface view.
4.
Enable periodic online user
reauthentication.
5.
(Optional.) Enable the
keep-online feature for
802.1X users.

Configuring an 802.1X guest VLAN

Configuration guidelines

When you configure an 802.1X guest VLAN, follow these guidelines:
You can configure only one 802.1X guest VLAN on a port. The 802.1X guest VLANs on different
ports can be different.
Command
system-view
dot1x timer reauth-period
reauth-period-value
interface interface-type
interface-number
dot1x re-authenticate
dot1x re-authenticate
server-unreachable
keep-online
86
Remarks
N/A
The default is 3600 seconds.
N/A
By default, the feature is disabled.
By default, this feature is disabled,
and the device logs off online
802.1X users if no authentication
server is reachable for 802.1X
reauthentication.

Advertisement

Table of Contents
loading

Table of Contents