HP 6125G HP 6125G & 6125G/XG Blade Switches Security Command Reference - Page 118

dot1x timer

Page 118 highlights

After the network access device sends an authentication request to a client, if the device receives no response from the client within the username request timeout timer (set with the dot1x timer tx-period tx-period-value command) or the client timeout timer (set with the dot1x timer supp-timeout supp-timeout-value command), the device retransmits the authentication request. The network access device stops retransmitting the request, if it has made the maximum number of request transmission attempts but still received no response. This command applies to all ports of the device. Related commands: display dot1x. Examples # Set the maximum number of attempts for sending an authentication request to a client as 9. system-view [Sysname] dot1x retry 9 dot1x timer Syntax dot1x timer { handshake-period handshake-period-value | quiet-period quiet-period-value | reauth-period reauth-period-value | server-timeout server-timeout-value | supp-timeout supp-timeout-value | tx-period tx-period-value } View undo dot1x timer { handshake-period | quiet-period | reauth-period | server-timeout | supp-timeout | tx-period } System view Default level 2: System level Parameters handshake-period-value: Sets the handshake timer in seconds, in the range of 5 to 1024. quiet-period-value: Sets the quiet timer in seconds, in the range of 10 to 120. reauth-period-value: Sets the periodic re-authentication timer in seconds, in the range of 60 to 7200. server-timeout-value: Sets the server timeout timer in seconds, in the range of 100 to 300. supp-timeout-value: Sets the client timeout timer in seconds, in the range of 1 to 120. tx-period-value: Sets the username request timeout timer in seconds, in the range of 10 to 120. Description Use dot1x timer to set 802.1X timers. Use undo dot1x timer to restore the defaults. By default, the handshake timer is 15 seconds, the quiet timer is 60 seconds, the periodic re-authentication timer is 3600 seconds, the server timeout timer is 100 seconds, the client timeout timer is 30 seconds, and the username request timeout timer is 30 seconds. You can set the client timeout timer to a high value in a low-performance network, set the quiet timer to a high value in a vulnerable network or a low value for quicker authentication response, or adjust the server timeout timer to adapt to the performance of different authentication servers. In most cases, the default settings are sufficient. 109

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291

109
After the network access device sends an authentication request to a client, if the device receives no
response from the client within the username request timeout timer (set with the
dot1x timer tx-period
tx-period-value
command) or the client timeout timer (set with the
dot1x timer supp-timeout
supp-timeout-value
command), the device retransmits the authentication request. The network access
device stops retransmitting the request, if it has made the maximum number of request transmission
attempts but still received no response.
This command applies to all ports of the device.
Related commands:
display dot1x
.
Examples
# Set the maximum number of attempts for sending an authentication request to a client as 9.
<Sysname> system-view
[Sysname] dot1x retry 9
dot1x timer
Syntax
dot1x timer
{
handshake-period
handshake-period-value
|
quiet-period
quiet-period-value
|
reauth-period
reauth-period-value
|
server-timeout
server-timeout-value
|
supp-timeout
supp-timeout-value
|
tx-period
tx-period-value
}
undo dot1x timer
{
handshake-period
|
quiet-period
|
reauth-period
|
server-timeout
|
supp-timeout
|
tx-period
}
View
System view
Default level
2: System level
Parameters
handshake-period-value
: Sets the handshake timer in seconds, in the range of 5 to 1024.
quiet-period-value
: Sets the quiet timer in seconds, in the range of 10 to 120.
reauth-period-value
: Sets the periodic re-authentication timer in seconds, in the range of 60 to 7200.
server-timeout-value
: Sets the server timeout timer in seconds, in the range of 100 to 300.
supp-timeout-value
: Sets the client timeout timer in seconds, in the range of 1 to 120.
tx-period-value
: Sets the username request timeout timer in seconds, in the range of 10 to 120.
Description
Use
dot1x
timer
to set 802.1X timers.
Use
undo dot1x
timer
to restore the defaults.
By default, the handshake timer is 15 seconds, the quiet timer is 60 seconds, the periodic
re-authentication timer is 3600 seconds, the server timeout timer is 100 seconds, the client timeout timer
is 30 seconds, and the username request timeout timer is 30 seconds.
You can set the client timeout timer to a high value in a low-performance network, set the quiet timer to
a high value in a vulnerable network or a low value for quicker authentication response, or adjust the
server timeout timer to adapt to the performance of different authentication servers. In most cases, the
default settings are sufficient.