Enterasys Networks N Standalone (NSA) Series Switch User Manual


  Open as PDF
of 1372
 
Security Configuration Command Set
Configuring 802.1X Authentication
Matrix NSA Series Configuration Guide 14-47
14.3.5.4 set dot1x auth-config
Use this command to configure 802.1X authentication.
set dot1x auth-config {[authcontrolled-portcontrol {auto | forced-auth |
forced-unauth}] [keytxenabled{false | true}] [maxreq value] [quietperiod
value] [reauthenabled {false | true}] [reauthperiod value] [servertimeout
timeout] [supptimeout timeout] [txperiod value]} [port-string]
Syntax Description
authcontrolled-
portcontrol auto |
forced-auth |
forced-unauth
Specifies the EAPOL port control mode as:
auto - Auto authorization mode (default). The Matrix
system will only forward frames received on a port
which are considered authenticated according to the
state of the corresponding access entity.
forced-auth - Forced authorized mode, which
effectively disables 802.1X authentication on the port,
and allows all frames received on the port to be
forwarded.
forced-unauth - Forced unauthorized mode, which
effectively disables 802.1X authentication on the port.
When 802.1X is the only active authentication agent on
a given port, this setting means all frames received will
be dropped.
keytxenabled
false | true
Enables (true) or disables (false) 802.1X key transmission
by the authenticator PAE state machine.
maxreq value Specifies the maximum number of authentication requests
allowed by the backend authentication state machine. Valid
values are 1 - 10.
quietperiod value Specifies the time (in seconds) following a failed
authentication before another attempt can be made by the
authenticator PAE state machine. Valid values are 0 -
65535.
reauthenabled
false | true
Enables (true) or disables (false) reauthentication control
of the reauthentication timer state machine.
reauthperiod
value
Specifies the time lapse (in seconds) between attempts by
the reauthentication timer state machine to reauthenticate a
port. Valid values are 0 - 65535.