Enabling The Periodic Online User Reauthentication Feature - HP FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Step
1.
Enter system view.
2.
Enable the quiet timer.
3.
(Optional.) Set the quiet
timer.
Enabling the periodic online user reauthentication
feature
Periodic online user reauthentication tracks the connection status of online users, and updates the
authorization attributes assigned by the server. The attributes include the ACL and VLAN. The
reauthentication interval is user configurable.
The server-assigned session timeout timer (Session-Timeout attribute) and termination action
(Termination-Action attribute) can affect the periodic online user reauthentication feature. To display
the server-assigned Session-Timeout and Termination-Action attributes, use the display dot1x
connection command (see Security Command Reference).
If the termination action is Default (logoff), periodic online user reauthentication on the device
takes effect only when the periodic reauthentication timer is shorter than the session timeout
timer.
If the termination action is Radius-request, the periodic online user reauthentication
configuration on the device does not take effect. The device reauthenticates the online 802.1X
users after the session timeout timer expires.
Support for the server configuration and assignment of session timeout timer and termination action
depends on the server model.
The VLANs assigned to an online user before and after reauthentication can be the same or
different.
You can set the perodic reauthenticaiton timer either in system view or in interface view. The
port-specific periodic reauthentication timer has higher priority than the global periodic
reauthentication timer.
To enable the periodic online user reauthentication feature:
Step
1.
Enter system view.
2.
(Optional.) Set the periodic
reauthentication timer.
3.
Enter Layer 2 Ethernet
interface view.
4.
Enable periodic online user
reauthentication.
5.
(Optional.) Enable the
keep-online feature for
802.1X users.
6.
(Optional.) Set the periodic
reauthentication timer.
Command
system-view
dot1x quiet-period
dot1x timer quiet-period
quiet-period-value
Command
system-view
dot1x timer reauth-period
reauth-period-value
interface interface-type
interface-number
dot1x re-authenticate
dot1x re-authenticate
server-unreachable
keep-online
dot1x timer reauth-period
reauth-period-value
91
Remarks
N/A
By default, the timer is disabled.
The default is 60 seconds.
Remarks
N/A
The default is 3600 seconds.
N/A
By default, the feature is disabled.
By default, this feature is
disabled. The device logs off
online 802.1X users if no
authentication server is reachable
for 802.1X reauthentication.
The default is 3600 seconds.

Advertisement

Table of Contents
loading

Table of Contents