333
DWS-1008 User’s Manual
D-Link Systems, Inc.
Managing 802.1X
Note:
If the number of reauthentications for a wired authentication client is greater than the
maximum number of reauthentications allowed, MSS sends an EAP failure packet to the
client and removes the client from the network. However, MSS does not remove a wireless
client from the network under these circumstances.
Setting the 802.1X Reauthentication Period
The following command configures the number of seconds that the switch waits before
attempting reauthentication:
set dot1x reauth-period
seconds
The default is 3600 seconds (1 hour). The range is from 60 to 1,641,600 seconds (19 days).
This value can be overridden by user authorization parameters.
MSS reauthenticates dynamic WEP clients based on the reauthentication timer. MSS also
reauthenticates WPA clients if the clients use the WEP-40 or WEP-104 cipher. For each
dynamic WEP client or WPA client using a WEP cipher, the reauthentication timer is set to
the lesser of the global setting or the value returned by the AAA server with the rest of the
authorization attributes for that client.
For example, type the following command to set the number of seconds to 100 before
reauthentication is attempted:
DWS-1008#
set dot1x reauth-period 100
success: dot1x auth-server timeout set to 100.
Type the following command to reset the default timeout period:
DWS-1008#
clear dot1x reauth-period
success: change accepted.
Setting the Bonded Authentication Period
The following command sets the Bonded Auth™ (bonded authentication) period, which is
the number of seconds MSS retains session information for an authenticated machine while
waiting for the 802.1X client on the machine to start (re)authentication for the user.
Normally, the Bonded Auth period needs to be set only if the network has Bonded Auth
clients that use dynamic WEP, or use WEP-40 or WEP-104 encryption with WPA or RSN.
These clients can be affected by the 802.1X reauthentication parameter or the RADIUS
Session-Timeout parameter.
To set the Bonded Auth period, use the following command:
set dot1x bonded-period
seconds
The Bonded Auth period applies only to 802.1X authentication rules that contain the
bonded
option.
Summary of Contents for DWS-1008
Page 1: ......