clear multiauth session-timeout
SecureStack C2 Configuration Guide 18-41
clear multiauth session-timeout
Usethiscommandtoresetthemaximumnumberofconsecutivesecondsanauthenticatedsession
maylastbeforeterminationofthesessiontoitsdefaultvalueof0.
Syntax
clear multiauth session-timeout [dot1x | mac | pwa]
Parameters
Defaults
Ifnoauthenticationmethodisspecified,thesessiontimeoutvalueisresettoitsdefaultvalueof0
forallauthenticationmethods.
Mode
Switchmode,read‐write.
Example
ThisexampleresetsthesessiontimeoutvaluefortheIEEE802.1Xauthenticationmethodto0
seconds.
C2(su)->clear multiauth session-timeout dot1x
Configuring VLAN Authorization (RFC 3580)
Purpose
RFC3580TunnelAttributesprovideamechanismtocontainan802.1Xauthenticatedusertoa
VLANregardlessofthe PVID.UptosixuserscanbeconfiguredperGigabitport.
Pleaseseesection3‐31ofRFC3580fordetailsonconfiguringaRADIUSservertoreturnthe
desiredtunnelattributes.
AsstatedinRFC3580,“...itmay bedesirabletoallowaporttobeplaced
intoaparticularVirtualLAN(VLAN),definedin[IEEE8021Q],basedontheresultofthe
authentication.”
TheRADIUSservertypicallyindicatesthedesiredVLANbyincludingtunnelattributeswithinits
Access‐Acceptparameters.However,
theIEEE802.1Xauthenticatorcanalsobeconfiguredto
instructtheVLANtobeassignedtothesupplicantbyincludingtunnelattributeswithinAccess‐
Requestparameters.
ThefollowingtunnelattributesareusedinVLANauthorizationassignment, :
•Tunnel‐Type‐VLAN(13)
•Tunnel‐Medium‐Type‐802
•Tunnel‐Private‐Group‐ID‐VLANID
dot1x (Optional)Specifies
theIEEE802.1Xport‐basednetworkaccesscontrol
authenticationmethodforwhichtoresetthetimeoutvaluetoits
default.
mac (Optional)SpecifiestheEnterasysMACauthenticationmethodfor
whichtoresetthetimeoutvaluetoitsdefault.
pwa (Optional)SpecifiestheEnterasysPortWebAuthenticationmethodfor
whichtoresetthetimeout
valuetoitsdefault.