3Com 4210 PWR Configuration Manual page 230

9/18/26 port and pwr 9/18/26 port 4210 series switch
Table of Contents

Advertisement

228
C
17: 802.1
HAPTER
c
Configuring 802.1x
Re-Authentication
n
Configuring the 802.1x
Re-Authentication Timer
C
X
ONFIGURATION
CAUTION:
The Guest VLAN function is available only when the switch operates in the
port-based authentication mode.
Only one Guest VLAN can be configured for each switch.
The Guest VLAN function cannot be implemented when the switch executes
the dot1x dhcp-launch command to enable DHCP-triggered authentication.
This is because that in that case the switch does not send authentication
packets.
Table 168 Enable 802.1x re-authentication
Operation
Enter system view
Enable
In system
802.1x
view
re-authentic
In port view
ation on
port(s)
To enable 802.1x re-authentication on a port, you must first enable 802.1x
globally and on the port.
After 802.1x re-authentication is enabled on the switch, the switch determines the
re-authentication interval in one of the following two ways:
1 The switch uses the value of the Session-timeout attribute field of the
Access-Accept packet sent by the RADIUS server as the re-authentication interval.
2 The switch uses the value configured with the dot1x timer reauth-period
command as the re-authentication interval for access users.
Note the following:
During re-authentication, the switch always uses the latest re-authentication
interval configured, no matter which of the above-mentioned two ways is used to
determine the re-authentication interval. For example, if you configure a
re-authentication interval on the switch and the switch receives an Access-Accept
packet whose Termination-Action attribute field is 1, the switch will ultimately use
the value of the Session-timeout attribute field as the re-authentication interval.
The following introduces how to configure the 802.1x re-authentication timer on
the switch.
Table 169 Configure the re-authentication interval
Operation
Enter system view
Configure a
re-authentication interval
Command
system-view
dot1x re-authenticate [
interface interface-list ]
dot1x re-authenticate
Command
system-view
dot1x timer reauth-period
reauth-period-value
Remarks
-
Required
By default, 802.1x
re-authentication is disabled on
a port.
Remarks
-
Optional
By default, the
re-authentication interval is
3,600 seconds.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents