13.07.2015 Views

Administration of the Avaya G350 Media Gateway - Avaya Support

Administration of the Avaya G350 Media Gateway - Avaya Support

Administration of the Avaya G350 Media Gateway - Avaya Support

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Managing login permissions4. Use <strong>the</strong> set dot1x system-auth-control enable command to enable 802.1xau<strong>the</strong>ntication on all ports set to auto mode. For example:<strong>G350</strong>-001(super)# set dot1x system-auth-control enableTo disable 802.1x au<strong>the</strong>ntication on <strong>the</strong> <strong>G350</strong>, use <strong>the</strong> command set dot1xsystem-auth-control disable.Once <strong>the</strong> au<strong>the</strong>ntication process is enabled, <strong>the</strong> process proceeds as follows:- The Supplicant is asked to supply a user name and password.- If 802.1x au<strong>the</strong>ntication is enabled on <strong>the</strong> port, <strong>the</strong> Au<strong>the</strong>nticator initiates au<strong>the</strong>nticationwhen <strong>the</strong> link is up.- When au<strong>the</strong>ntication is completed, <strong>the</strong> Supplicant receives a Permit/Deny notification.- Au<strong>the</strong>ntication fails if:- <strong>the</strong> Supplicant fails to respond to requests from <strong>the</strong> Au<strong>the</strong>nticator- Management controls prevent <strong>the</strong> port from being authorized- The link is down- The user supplied incorrect login information.5. For additional security, use <strong>the</strong> set port dot1x re-au<strong>the</strong>ntication command,followed by <strong>the</strong> module and port number (or a range <strong>of</strong> ports) to enable re-au<strong>the</strong>ntication ona port or a group <strong>of</strong> ports. By default, re-au<strong>the</strong>ntication is disabled. For example:<strong>G350</strong>-001(super)# set port dot1x re-au<strong>the</strong>ntication 6/4-6 enableTo disable re-au<strong>the</strong>ntication, use this command set port dot1x re-au<strong>the</strong>nticationmodule/port disable.6. By default, <strong>the</strong> re-au<strong>the</strong>ntication period is 3600 seconds. In o<strong>the</strong>r words, if re-au<strong>the</strong>nticationis enabled on a port, <strong>the</strong> port attempts to re-au<strong>the</strong>nticate <strong>the</strong> host every 3600 seconds. Tochange <strong>the</strong> re-au<strong>the</strong>ntication period, use <strong>the</strong> set dot1x re-authperiod command,followed by <strong>the</strong> length <strong>of</strong> <strong>the</strong> new re-au<strong>the</strong>ntication period in seconds (0 to 65535). Forexample:<strong>G350</strong>-001(super)# set port dot1x re-authperiod 6/4 400Issue 3 January 2005 43

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!