Configuring 802.1x Re-Authentication

Follow these steps to enable 802.1x re-authentication:

 

To do…

Use the command…

Remarks

 

 

Enter system view

system-view

 

 

 

 

 

 

 

 

 

 

 

Required

 

 

Enable 802.1x globally

dot1x

By default, 802.1x is disabled

 

 

 

 

 

globally.

 

 

 

 

 

 

 

 

Enable

In system view

dot1x [ interface interface-list]

Required

 

 

802.1x for

 

 

By default, 802.1x is disabled

 

 

 

 

 

 

specified

In port view

dot1x

 

 

on all ports.

 

 

ports

 

 

 

 

 

 

 

 

 

 

 

 

 

Enable

In system view

dot1x re-authenticate

Required

 

 

802.1x

[ interface interface-list ]

By default, 802.1x

 

 

 

 

 

re-authenticat

 

 

re-authentication is disabled

 

 

In port view

dot1x re-authenticate

 

 

ion on port(s)

on a port.

 

 

 

 

 

 

 

 

 

 

 

 

 

To enable 802.1x re-authentication on a port, you must first enable 802.1x globally and on the port.

Configuring the 802.1x Re-Authentication Timer

After 802.1x re-authentication is enabled on the device, the device determines the re-authentication interval in one of the following two ways:

1)The device uses the value of the Session-timeout attribute field of the Access-Accept packet sent by the RADIUS server as the re-authentication interval.

2)The device uses the value configured with the dot1x timer reauth-periodcommand as the re-authentication interval for access users.

Note the following:

During re-authentication, the device always uses the latest re-authentication interval configured, no matter which of the above-mentioned two ways is used to determine the re-authentication interval. For example, if you configure a re-authentication interval on the device and the device receives an Access-Accept packet whose Termination-Action attribute field is 1, the device will ultimately use the value of the Session-timeout attribute field as the re-authentication interval.

The following introduces how to configure the 802.1x re-authentication timer on the device.

1-18

Page 239
Image 239
3Com WX3000 Configuring 802.1x Re-Authentication, Configuring the 802.1x Re-Authentication Timer, Dot1x re-authenticate