Yamaha 10G SWR2310-28GT/18GT/10G Command Reference - Page 145

Set re-authentication

Page 145 highlights

Operation mode single-host multi-host multi-supplicant Command Reference | Interface control | 145 Description This mode allows communications for only one supplicant per port. Only the first supplicant that passes authentication is allowed. This mode allows communication with multiple supplicants for each port. If the first supplicant passes authentication, all other supplicants of the same port will be allowed to communicate without authentication. This mode allows communication with multiple supplicants for each port. Communication is allowed or denied on a per-supplicant basis. [Initial value] auth host-mode single-host [Input mode] interface mode [Description] Changes the port authentication operation mode for the applicable interface. If this command is executed with the "no" syntax, the setting returns to the default. [Note] This command can be specified only for both LAN/SFP port and logical interface. Changing the settings for this command will make the authentication state return to the default. When using dynamic VLAN in multi-supplicant mode, the VLAN can be specified for individual supplicants. When using dynamic VLAN in multi-host, the VLAN ID applied by the first supplicant will be applied to supplicants from the second onwards. To use this command, you must enable the port authentication function for the applicable interface. (dot1x port-control command, auth-mac enable command, auth-web enable command) [Example] Change the LAN port #1 to multi supplicant mode. SWR2310(config)#interface port1.1 SWR2310(config-if)#auth host-mode multi-supplicant 5.3.11 Set re-authentication [Syntax] auth reauthentication no auth reauthentication [Initial value] no auth reauthentication [Input mode] interface mode [Description] Enables reauthentication of supplicants for the applicable interface. If this is executed with the "no" syntax, the re-authentication is disabled. When this setting is enabled, this periodically reauthenticates supplicants that have been successfully authenticated. The reauthentication interval can be changed using the auth timeout reauth-period command. [Note] This command can be specified only for both LAN/SFP port and logical interface. During IEEE 802.1X authentication, an EAPOL packet is transmitted to the supplicant at the timing for reauthentication to once again retrieve the user information, and an authentication request is sent to the RADIUS server. During MAC authentication, the supplicant's MAC address is regarded as a user name and password at the timing for reauthentication, and a request is sent to the RADIUS server for authentication.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278

Operation mode
Description
single-host
This mode allows communications for only one
supplicant per port. Only the first supplicant that
passes authentication is allowed.
multi-host
This mode allows communication with multiple
supplicants for each port. If the first supplicant
passes authentication, all other supplicants of the
same port will be allowed to communicate
without authentication.
multi-supplicant
This mode allows communication with multiple
supplicants for each port. Communication is
allowed or denied on a per-supplicant basis.
[Initial value]
auth host-mode single-host
[Input mode]
interface mode
[Description]
Changes the port authentication operation mode for the applicable interface.
If this command is executed with the "no" syntax, the setting returns to the default.
[Note]
This command can be specified only for both LAN/SFP port and logical interface.
Changing the settings for this command will make the authentication state return to the default.
When using dynamic VLAN in multi-supplicant mode, the VLAN can be specified for individual supplicants.
When using dynamic VLAN in multi-host, the VLAN ID applied by the first supplicant will be applied to supplicants from the
second onwards.
To use this command, you must enable the port authentication function for the applicable interface. (
dot1x port-control
command,
auth-mac enable
command,
auth-web enable
command)
[Example]
Change the LAN port #1 to multi supplicant mode.
SWR2310(config)#interface port1.1
SWR2310(config-if)#auth host-mode multi-supplicant
5.3.11 Set re-authentication
[Syntax]
auth
reauthentication
no
auth
reauthentication
[Initial value]
no auth reauthentication
[Input mode]
interface mode
[Description]
Enables reauthentication of supplicants for the applicable interface.
If this is executed with the "no" syntax, the re-authentication is disabled.
When this setting is enabled, this periodically reauthenticates supplicants that have been successfully authenticated.
The reauthentication interval can be changed using the
auth timeout reauth-period
command.
[Note]
This command can be specified only for both LAN/SFP port and logical interface.
During IEEE 802.1X authentication, an EAPOL packet is transmitted to the supplicant at the timing for reauthentication to once
again retrieve the user information, and an authentication request is sent to the RADIUS server.
During MAC authentication, the supplicant's MAC address is regarded as a user name and password at the timing for
reauthentication, and a request is sent to the RADIUS server for authentication.
Command Reference | Interface control |
145