Set portaccess port authenticator – Allied Telesis AT-S60 User Manual

Page 280

background image

Chapter 26: 802.1x Port-Based Access Control Commands

278

SET PORTACCESS PORT AUTHENTICATOR

Syntax

set portaccess port=port|all authenticator
[control=auto|forceauthenticate|
forceunauthenticate] [quietperiod=integer]
[txperiod=integer] [reauthperiod=integer]
[supptimeOut=integer] [servtimeout=integer]
[maxreq=integer]

Parameters

port

Specifies the port whose Authenticator settings you
want to set. You can specify more than one port at a
time. To set all ports, specify ALL. The selected ports
must already be set to the Authenticator role. To set
port role, see SET PORTACCESS PORT ROLE on page
280.

control

This parameter can take the following values:

Force-authenticate: Disables 802.1X port-based
authentication and causes the port to transition to the
authorized state without any authentication
exchange required. The port transmits and receives
normal traffic without 802.1X-based authentication of
the client.

Force-unauthenticate: Causes the port to remain in
the unauthorized state, ignoring all attempts by the
client to authenticate. The switch cannot provide
authentication services to the client through the
interface.

Auto: Enables 802.1X port-based authentication and
causes the port to begin in the unauthorized state,
allowing only EAPOL frames to be sent and received
through the port. The authentication process begins
when the link state of the port changes. The switch
requests the identity of the client and begins relaying
authentication messages between the client and the
authentication server. Each client that attempts to
access the network is uniquely identified by the switch
by using the client's MAC address. This is the default
setting.