194
C
HAPTER
24: C
ENTRALIZED
MAC A
DDRESS
A
UTHENTICATION
C
ONFIGURATION
Centralized MAC
Address
Authentication
Configuration
Example
Centralized MAC address authentication configuration is similar to 802.1x. In this
example, the differences between the two lie in the following:
Centralized MAC address authentication needs to be enabled both globally and for
port.
In MAC address mode, Mac address of locally authenticated user is used as both user
name and password.
In MAC address mode, MAC address of user authenticated by RADIUS server need to
be configured as both user name and password on the RADIUS server.
The following section describes how to enable centralized MAC address
authentication globally and for a port, and how to configure a local user. For other
related configuration, refer to the configuration examples in Chapter 21.
1
Enable centralized MAC address authentication for GigabitEthernet 1/0/2 port.
<S4200G>
system-view
[4200G]
mac-authentication interface GigabitEthernet 1/0/2
2
Configure centralized MAC address authentication mode as MAC address mode.
[4200G]
mac-authentication authmode usernameasmacaddress
3
Add a local user.
a
Configure the user name and password.
[4200G]
local-user 00-e0-fc-01-01-01
[4200G-luser-00-e0-fc-01-01-01]
password simple 00-e0-fc-01-01-01
b
Set service type of the local user to lan-access.
[4200G-luser-00-e0-fc-01-01-01]
service-type lan-access
4
Enable centralized MAC address authentication globally.
[4200G]
mac-authentication
5
Configure the domain name for centralized MAC address authentication users as
aabbcc163.net.
[4200G]
mac-authentication domain aabbcc163.net
For domain-related configuration, refer to Chapter 21.
Summary of Contents for 3CR17660-91
Page 10: ...8 CONTENTS ...
Page 14: ...4 ABOUT THIS GUIDE ...
Page 46: ...32 CHAPTER 5 LOGGING IN THROUGH WEB BASED NETWORK MANAGEMENT SYSTEM ...
Page 48: ...34 CHAPTER 6 LOGGING IN THROUGH NMS ...
Page 60: ...46 CHAPTER 9 VLAN CONFIGURATION ...
Page 64: ...50 CHAPTER 10 MANAGEMENT VLAN CONFIGURATION ...
Page 80: ...66 CHAPTER 13 GVRP CONFIGURATION ...
Page 98: ...84 CHAPTER 15 LINK AGGREGATION CONFIGURATION ...
Page 112: ...98 CHAPTER 18 MAC ADDRESS TABLE MANAGEMENT ...
Page 126: ...112 CHAPTER 19 LOGGING IN THROUGH TELNET ...
Page 162: ...148 CHAPTER 20 MSTP CONFIGURATION ...
Page 274: ...260 CHAPTER 29 IGMP SNOOPING CONFIGURATION ...
Page 276: ...262 CHAPTER 30 ROUTING PORT JOIN TO MULTICAST GROUP CONFIGURATION ...
Page 298: ...284 CHAPTER 33 SNMP CONFIGURATION ...
Page 304: ...290 CHAPTER 34 RMON CONFIGURATION ...
Page 338: ...324 CHAPTER 36 SSH TERMINAL SERVICES ...
Page 356: ...342 CHAPTER 38 FTP AND TFTP CONFIGURATION ...
Page 365: ...Information Center Configuration Example 351 S4200G terminal logging ...
Page 366: ...352 CHAPTER 39 INFORMATION CENTER ...
Page 378: ...364 CHAPTER 40 BOOTROM AND HOST SOFTWARE LOADING ...
Page 384: ...370 CHAPTER 41 Basic System Configuration and Debugging ...
Page 388: ...374 CHAPTER 43 NETWORK CONNECTIVITY TEST ...
Page 406: ...392 CHAPTER 45 CONFIGURATION OF NEWLY ADDED CLUSTER FUNCTIONS ...