Specifications

Configuring 802.1X Authentication
17-16 Configuring AAA for Network Users
host/*.mycorp.com(userglobforthemachineauthenticationrule)
•*.mycorp.com(userglobfortheuserauthenticationrule)
Ifthedomainnamehasmorenodes(forexample,nl.mycorp.com),useanasteriskineachnode
thatyouwanttomatchglobally.Forexample,tomatchonallmachinesandusersinmycorp.com,
usethefollowinguserglobs:
host/*.*.mycorp.com
(userglobforthe machineauthenti cationrule)
•*.*.mycorp.com(userglobfortheuserauthenticationrule)
Usemorespecificrulestodirectmachinesanduserstodifferentservergroups.Forexample,to
directusersinnl.mycorp.comtoadifferentservergroupthanusersinde.mycorp.com,usethe
followinguserglobs:
host/*.nl.mycorp.com(userglobforthemachineauthentication
rule)
•*.nl.mycorp.com(userglobfortheuserauthenticationrule)
host/*.de.mycorp.com(userglobforthemachineauthenticationrule)
•*.de.mycorp.com(userglobfortheuserauthenticationrule)
Bonded Auth Period
TheBondedAuthperiodisthenumberofsecondsMSSallowsaBondedAuthuserto
reauthenticate.
Aftersuccessfulmachineauthentication,asessionforthemachineappearsinthesessiontablein
MSS.Whentheuserlogsonandisauthenticated,theusersessionreplacesthemachinesessionin
thetable.
However,sincetheusersauthenticationrulecontainsthebondedoption,MSS
remembersthatthemachinewasauthenticated.
IfaBondedAuthuserssessionisendeddueto802.1XreauthenticationortheRADIUSSession
Timeoutparameter,MSScanallowtimefortheusertoreauthenticate.Theamountoftimethat
MSSallows
forreauthenticationiscontrolledbytheBondedAuthperiod.
IftheuserdoesnotreauthenticatewithintheBondedAuthperiod,MSSdeletestheinformation
aboutthemachinesession.Afterthemachinesessioninformationisdeleted,theBondedAuth
usercannotreauthenticate.Whenthisoccurs,theuserwillneedtologoff,
thenlogbackon,to
accessthenetwork.Aftermultiplefailedreauthenticationattempts,theusermightneedtoreboot
thePCbeforeloggingon.
Bydefault,theBondedAuthperiodis0seconds.MSSdoesnotwaitforaBondedAuthuserto
reauthenticate.
YoucansettheBondedAuth
periodtoavalueupto300seconds.EnterasysNetworks
recommendsthatyoutry60seconds,andchangetheperiodtoalongervalueonlyifclientsare
unabletoauthenticatewithin60seconds.
TosettheBondedAuthperiod,usethefollowingcommand:
set dot1x bonded-period seconds
ToresettheBondedAuthperiodtoitsdefaultvalue(0),usethefollowingcommand:
clear dot1x bonded-period