Specifications
Configuring 802.1X Authentication
17-16 Configuring AAA for Network Users
• host/*.mycorp.com(userglobforthemachineauthenticationrule)
•*.mycorp.com(userglobfortheuserauthenticationrule)
Ifthedomainnamehasmorenodes(forexample,nl.mycorp.com),useanasteriskineachnode
thatyouwanttomatchglobally.Forexample,tomatchonallmachinesandusersinmycorp.com,
usethefollowinguserglobs:
• host/*.*.mycorp.com
(userglobforthe machineauthenti cationrule)
•*.*.mycorp.com(userglobfortheuserauthenticationrule)
Usemorespecificrulestodirectmachinesanduserstodifferentservergroups.Forexample,to
directusersinnl.mycorp.comtoadifferentservergroupthanusersinde.mycorp.com,usethe
followinguserglobs:
• host/*.nl.mycorp.com(userglobforthemachineauthentication
rule)
•*.nl.mycorp.com(userglobfortheuserauthenticationrule)
• host/*.de.mycorp.com(userglobforthemachineauthenticationrule)
•*.de.mycorp.com(userglobfortheuserauthenticationrule)
Bonded Auth Period
TheBondedAuthperiodisthenumberofsecondsMSSallowsaBondedAuthuserto
reauthenticate.
Aftersuccessfulmachineauthentication,asessionforthemachineappearsinthesessiontablein
MSS.Whentheuserlogsonandisauthenticated,theusersessionreplacesthemachinesessionin
thetable.
However,sincetheuser’sauthenticationrulecontainsthebondedoption,MSS
remembersthatthemachinewasauthenticated.
IfaBondedAuthuser’ssessionisendeddueto802.1XreauthenticationortheRADIUSSession‐
Timeoutparameter,MSScanallowtimefortheusertoreauthenticate.Theamountoftimethat
MSSallows
forreauthenticationiscontrolledbytheBondedAuthperiod.
IftheuserdoesnotreauthenticatewithintheBondedAuthperiod,MSSdeletestheinformation
aboutthemachinesession.Afterthemachinesessioninformationisdeleted,theBondedAuth
usercannotreauthenticate.Whenthisoccurs,theuserwillneedtologoff,
thenlogbackon,to
accessthenetwork.Aftermultiplefailedreauthenticationattempts,theusermightneedtoreboot
thePCbeforeloggingon.
Bydefault,theBondedAuthperiodis0seconds.MSSdoesnotwaitforaBondedAuthuserto
reauthenticate.
YoucansettheBondedAuth
periodtoavalueupto300seconds.EnterasysNetworks
recommendsthatyoutry60seconds,andchangetheperiodtoalongervalueonlyifclientsare
unabletoauthenticatewithin60seconds.
TosettheBondedAuthperiod,usethefollowingcommand:
set dot1x bonded-period seconds
ToresettheBondedAuthperiodtoitsdefaultvalue(0),usethefollowingcommand:
clear dot1x bonded-period