Command Manual (For Soliton) – 802.1x-System Guard
H3C S3100 Series Ethernet Switches
Chapter 1 802.1x Configuration Commands
1-20
z
Sends Trap packets without disconnecting the user, which can be achieved by
using the
dot1x supp-proxy-check trap
command.
This function needs the cooperation of 802.1x clients and the CAMS server:
z
Multiple network adapter checking, proxy checking, and IE proxy checking are
enabled on the 802.1x client.
z
The CAMS server is configured to disable the use of multiple network adapters,
proxies, and IE proxy.
By default, proxy checking is disabled on 802.1x client. In this case, if you configure the
CAMS server to disable the use of multiple network adapters, proxies, and IE proxy, it
sends messages to the 802.1x client to ask the latter to disable the use of multiple
network adapters, proxies, and IE proxy after the user passes the authentication.
Note:
z
The 802.1x proxy checking function needs the cooperation of H3C's 802.1x client
program.
z
The proxy checking function takes effect only after the client version checking
function is enabled on the switch (using the
dot1x version-check
command).
Related command:
display dot1x
.
Example
# Configure to disconnect the users connected to Ethernet1/0/1 through Ethernet1/0/8
ports if they are detected logging in through proxies.
<Sysname> system-view
System View: return to User View with Ctrl+Z.
[Sysname] dot1x supp-proxy-check logoff
[Sysname] dot1x supp-proxy-check logoff interface Ethernet 1/0/1 to Ethernet
1/0/8
# Configure the switch to send Trap packets if the users connected to Ethernet1/0/9
port is detected logging in through proxies.
[Sysname] dot1x supp-proxy-check trap
[Sysname] dot1x supp-proxy-check trap interface Ethernet 1/0/9
1.1.16 dot1x timer
Syntax
dot1x timer
{
handshake-period
handshake-period-value
|
quiet-period
quiet-period-value
|
server-timeout
server-timeout-value
|
supp-timeout