Switch User Manual

clear multiauth session-timeout
26-48 Authentication and Authorization Configuration
clear multiauth session-timeout
Usethiscommandtoresetthemaximumnumberofconsecutivesecondsanauthenticatedsession
maylastbeforeterminationofthesessiontoitsdefaultvalueof0.
Syntax
clear multiauth session-timeout [dot1x | mac | pwa]
Parameters
Defaults
Ifnoauthenticationmethodisspecified,thesessiontimeoutvalueisresettoitsdefaultvalueof0
forallauthenticationmethods.
Mode
Switchmode,readwrite.
Example
ThisexampleresetsthesessiontimeoutvaluefortheIEEE802.1Xauthenticati onmethodto0
seconds.
C3(su)->clear multiauth session-timeout dot1x
Configuring User + IP Phone Authentication
User+IPphoneauthenticationisalegacyfeaturethatallowsauserandtheirIPphonetobothuse
asingleportonthe
switch buttohaveseparatepolicyroles.TheusersPCandtheirIPphoneare
daisychainedtogetherwithasingleconnectiontothenetwork.
Thisspecialapplicationofmultiuserauthenticationwasinheritedfromlegacyplatforms(suchas
theB2andC2)thatcouldnotnativelysupportmultipleusersperport.
TheSecureStackC3can
supportmultipleusersperportsotheUser+IPphoneapplicationshouldonlybeusedifyouare
integratingSecureStackC3sintoalegacydeployment.
WithʺUser+IPPhoneʺauthentication,thepolicyrolefortheIPphoneisstaticallymappedusing
apolicyadminrule
whichassignsanypacketsreceivedwithaVLANtagsettoaspecificVID(for
example,VoiceVLAN)toanspecifiedpolicyrole(forexample,IPPhonepolicyrole).Therefore,it
isrequiredthattheIPphonebeconfiguredtosendVLANtaggedpacketstaggedforthe“Voice”
VLAN.Referto
theUsagesectionforthecommandsetpolicyruleonpage 1110foradditional
informationaboutconfiguringapolicyadminrulethatmapsaVLANtagtoapolicyrole.
NotethatiftheIPphoneauthenticatestothe network,theRADIUSacceptmessagemustreturn
nullvaluesforRFC
3580tunnelattributesand theFilterID.
dot1x (Optional)SpecifiestheIEEE802.1Xportbasednetworkaccesscontrol
authenticationmethodforwhichtoresetthetimeoutvaluetoits
default.
mac (Optional)SpecifiestheEnterasysMACauthenticationmethodfor
whichtoresetthetimeoutvaluetoitsdefault.
pwa (Optional)SpecifiestheEnterasys
PortWebAuthenticationmethodfor
whichtoresetthetimeoutvaluetoitsdefault.