xStack
®
DGS-3600 Series Layer 3 Gigabit Ethernet Managed Switch CLI Manual
238
config 802.1x auth_parameter
Purpose
Used to configure the 802.1X authentication parameters on a range of
ports. The default parameter will return all ports in the specified range to
their default 802.1X settings.
Syntax
config 802.1x auth_parameter ports [<portlist> | all] [default |
{direction [both | in] | port_control [force_unauth | auto | force_auth] |
quiet_period <sec 0-65535> | tx_period <sec 1-65535> | supp_timeout
<sec 1-65535> | server_timeout <sec 1-65535> | max_req <value 1-10>
| reauth_period <sec 1-65535> | enable_reauth [enable | disable]}]
Description
The
config 802.1x auth_parameter
command is used to configure the
802.1X Authentication parameters on a range of ports. The default
parameter will return all ports in the specified range to their default 802.1X
settings.
Parameters
<portlist>
−
Specifies a port or range of ports to be configured. The
beginning and end of the port list range are separated by a dash. Non-
contiguous portlist entries are separated by a comma. (ex: 1-3, 7-9)
all
−
Specifies all of the ports on the Switch.
default
−
Returns all of the ports in the specified range to their 802.1X
default settings.
direction [both | in]
−
Determines whether a controlled port blocks
communication in both the receiving and transmitting directions, or just the
receiving direction.
port_control
−
Configures the administrative control over the authentication
process for the range of ports. The user has the following authentication
options:
•
force_auth
−
Forces the Authenticator for the port to become
authorized. Network access is allowed.
•
auto
−
Allows the port’s status to reflect the outcome of the
authentication process.
•
force_unauth
−
Forces the Authenticator for the port to become
unauthorized. Network access will be blocked.
quiet_period <sec 0-65535>
−
Configures the time interval between
authentication failure and the start of a new authentication attempt.
tx_period <sec 1-65535>
−
Configures the time to wait for a response from
a supplicant (user) to send EAP Request/Identity packets.
supp_timeout <sec 1-65535>
−
Configures the time to wait for a response
from a supplicant (user) for all EAP packets, except for the Request/Identity
packets.
server_timeout <sec 1-65535>
−
Configure the length of time to wait for a
response from a RADIUS server.
max_req <value 1-10>
−
Configures the number of times to retry sending
packets to a supplicant (user).
reauth_period <sec 1-65535>
−
Configures the time interval between
successive re-authentications.
enable_reauth [enable | disable]
−
Determines whether or not the Switch
will re-authenticate. Enabled causes re-authentication of users at the time
interval specified in the Re-authentication Period field, above.
Restrictions
Only Administrator and Operator-level users can issue this command.
Example usage:
To configure 802.1X authentication parameters for ports 1 to 10: