Product manual

Manage 802.1X on the device port(s).
Next Available Options:
control < authorized | auto | unauthorized > -- Set the authenticator to Force Authorized, Force
Unauthorized or Auto state (default Auto). (NUMBER) (p. 32)
quiet-period < 0 to 65535 > -- Set the period of time the switch does not try to acquire a
supplicant (default 60 sec.). (NUMBER) (p. 46)
tx-period < 1 to 65535 > -- Set the period of time the switch waits until retransmission of EAPOL
PDU (default 30 sec.). (NUMBER) (p. 52)
supplicant-timeout < 1 to 300 > -- Set the supplicant response timeout on an EAP request
(default 30 sec.). (NUMBER) (p. 51)
server-timeout < 1 to 300 > -- Set the authentication server response timeout (default 30sec.).
(NUMBER) (p. 49)
max-requests < 1 to 10 > -- Set maximum number of times the switch retransmits authentication
requests (default 2). (NUMBER) (p. 39)
reauth-period < 0 to 9999999 > -- Set the re-authentication timeout (in seconds, default 0); set
to '0' to disable re-authentication. (NUMBER) (p. 47)
auth-vid -- Configures VLAN where to move port after successful authentication (not configured
by default).(p. 30)
unauth-vid -- Configures VLAN where to keep port while there is an unauthenticated client
connected (not configured by default).(p. 52)
unauth-period < 0 to 255 > -- Set period of time the switch waits for authentication before
moving the port to the VLAN for unauthenticated clients. (NUMBER) (p. 52)
logoff-period < 1 to 999999999 > -- Set period of time after which a client will be considered
removed from the port for a lack of activity. (NUMBER) (p. 36)
client-limit -- Set the maximum number of clients to allow on the port.(p. 31)
initialize -- Reinitialize the authenticator state machine.(p. 35)
reauthenticate -- Force re-authentication to happen.(p. 47)
clear-statistics -- Clear the authenticator statistics.(p. 31)
[no] aaa port-access [ETHERNET] PORT-LIST
Manage general port security features on the device port(s).
Next Available Option:
controlled-direction < both | in > -- Configure how traffic is controlled on non-authenticated
ports; in BOTH directions (ingress+egress) or IN only (ingress). (NUMBER) (p. 33)
primary
aaa authentication console enable < local | tacacs | radius >
Specify the primary authentication method for access control.
Supported Values:
local -- Use local switch user/password database.
tacacs -- Use TACACS+ server.
radius -- Use RADIUS server.
Next Available Option:
secondary < local | none | authorized > -- Specify the backup authentication method for access
control.(p. 47)
43© 2008 Hewlett-Packard Development Company, L.P.
aaaCommand Line Interface Reference Guide