11.07.2015 Views

Catalyst 3750-E and 3560-E Switch Cisco IOS ... - DNIP . NET

Catalyst 3750-E and 3560-E Switch Cisco IOS ... - DNIP . NET

Catalyst 3750-E and 3560-E Switch Cisco IOS ... - DNIP . NET

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 2<strong>Catalyst</strong> <strong>3750</strong>-E <strong>and</strong> <strong>3560</strong>-E <strong>Switch</strong> <strong>Cisco</strong> <strong>IOS</strong> Comm<strong>and</strong>sdot1x timeoutComm<strong>and</strong> HistoryRelease12.2(35)SE212.2(40)SEModificationThis comm<strong>and</strong> was introduced.The range for tx-period seconds is incorrect. The correct range is from 1 to65535.Usage GuidelinesYou should change the default value of this comm<strong>and</strong> only to adjust for unusual circumstances such asunreliable links or specific behavioral problems with certain clients <strong>and</strong> authentication servers.The dot1x timeout reauth-period interface configuration comm<strong>and</strong> affects the behavior of the switchonly if you have enabled periodic re-authentication by using the dot1x reauthentication interfaceconfiguration comm<strong>and</strong>.During the quiet period, the switch does not accept or initiate any authentication requests. If you wantto provide a faster response time to the user, enter a number smaller than the default.When the ratelimit-period is set to 0 (the default), the switch does not ignore EAPOL packets fromclients that have been successfully authenticated <strong>and</strong> forwards them to the RADIUS server.ExamplesThis example shows how to enable periodic re-authentication <strong>and</strong> to set 4000 as the number of secondsbetween re-authentication attempts:<strong>Switch</strong>(config-if)# dot1x reauthentication<strong>Switch</strong>(config-if)# dot1x timeout reauth-period 4000This example shows how to enable periodic re-authentication <strong>and</strong> to specify the value of theSession-Timeout RADIUS attribute as the number of seconds between re-authentication attempts:<strong>Switch</strong>(config-if)# dot1x reauthentication<strong>Switch</strong>(config-if)# dot1x timeout reauth-period serverThis example shows how to set 30 seconds as the quiet time on the switch:<strong>Switch</strong>(config-if)# dot1x timeout quiet-period 30This example shows how to set 45 seconds as the switch-to-authentication server retransmission time:<strong>Switch</strong>(config)# dot1x timeout server-timeout 45This example shows how to set 45 seconds as the switch-to-client retransmission time for the EAPrequest frame:<strong>Switch</strong>(config-if)# dot1x timeout supp-timeout 45This example shows how to set 60 as the number of seconds to wait for a response to anEAP-request/identity frame from the client before re-transmitting the request:<strong>Switch</strong>(config-if)# dot1x timeout tx-period 60This example shows how to set 30 as the number of seconds that the switch ignores EAPOL packets fromsuccessfully authenticated clients:<strong>Switch</strong>(config-if)# dot1x timeout ratelimit-period 30You can verify your settings by entering the show dot1x privileged EXEC comm<strong>and</strong>.OL-9776-08<strong>Catalyst</strong> <strong>3750</strong>-E <strong>and</strong> <strong>3560</strong>-E <strong>Switch</strong> Comm<strong>and</strong> Reference2-179

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!