02.10.2013 Views

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

To configure <strong>the</strong> quiet period after a failed au<strong>the</strong>ntication:<br />

Step Task Command Syntax Command Mode<br />

1 Configure <strong>the</strong> amount of time that <strong>the</strong><br />

au<strong>the</strong>nticator waits to re-transmit a Request<br />

Identity frame after a failed au<strong>the</strong>ntication.<br />

Figure 479 shows configuration in<strong>for</strong>mation <strong>for</strong> a port <strong>for</strong> which <strong>the</strong> au<strong>the</strong>nticator re-transmits an EAP<br />

Request Identity frame:<br />

• after 90 seconds and a maximum of 10 times <strong>for</strong> an unresponsive supplicant<br />

• Re-transmits an EAP Request Identity frame<br />

Figure 479 Configuring a Request Identity Re-transmissions<br />

<strong>Force10</strong>(conf-if-range-gi-2/1)#dot1x tx-period 90<br />

<strong>Force10</strong>(conf-if-range-gi-2/1)#dot1x max-eap-req 10<br />

<strong>Force10</strong>(conf-if-range-gi-2/1)#dot1x quiet-period 120<br />

<strong>Force10</strong>#show dot1x interface gigabite<strong>the</strong>rnet 2/1<br />

802.1x in<strong>for</strong>mation on Gi 2/1:<br />

-----------------------------<br />

Dot1x Status: Enable<br />

Port Control: AUTO<br />

Port Auth Status: UNAUTHORIZED<br />

Re-Au<strong>the</strong>ntication: Disable<br />

Untagged VLAN id: None<br />

Tx Period: 90 seconds<br />

Quiet Period: 120 seconds<br />

ReAuth Max: 2<br />

Supplicant Timeout: 30 seconds<br />

Server Timeout: 30 seconds<br />

Re-Auth Interval: 3600 seconds<br />

Max-EAP-Req: 10<br />

Auth Type: SINGLE_HOST<br />

Auth PAE State: Initialize<br />

Backend State: Initialize<br />

dot1x quiet-period seconds<br />

Range: 1-65535<br />

Default: 60<br />

New Re-transmit Interval<br />

New Quiet Period<br />

New Maximum Re-transmissions<br />

Forcibly Authorizing or Unauthorizing a Port<br />

IEEE 802.1X requires that a port can be manually placed into any of three states:<br />

INTERFACE<br />

• ForceAuthorized is an authorized state. A device connected to this port in this state is never subjected<br />

to <strong>the</strong> au<strong>the</strong>ntication process, but is allowed to communicate on <strong>the</strong> network. Placing <strong>the</strong> port in this<br />

state is same as disabling 802.1X on <strong>the</strong> port.<br />

680 802.1X

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!