1-5
z
userLogin
specifies port-based 802.1X authentication.
z
macAddress
specifies MAC address authentication.
z
Else
specifies that the authentication method before
Else
is applied first. If the authentication fails,
the protocol type of the authentication request determines whether to turn to the authentication
method following the
Else
.
z
In a security mode with
Or
, the protocol type of the authentication request determines which
authentication method is to be used. However, 802.1X authentication is preferred by wireless
users.
z
userLogin with Secure
specifies MAC-based 802.1X authentication.
z
Ext
indicates allowing multiple 802.1X users to be authenticated and get online. A security mode
without
Ext
allows only one 802.1X user to be authenticated and get online.
Support for Guest VLAN
A MAC authentication guest VLAN is the VLAN that a user is in after failing authentication.
For a security mode that supports MAC authentication, you can configure a MAC-based guest VLAN
(MAC authentication MGV). For details about MAC authentication MGV, refer to
MAC Authentication
Configuration
in the
Security Volume
.
Port Security Configuration Task List
Complete the following tasks to configure port security:
Task
Remarks
Enabling Port Security
Required
Setting the Maximum Number of Secure MAC Addresses
Optional
Setting the Port Security Mode
Required
Configuring NTK
Configuring Intrusion Protection
Configuring Port Security Features
Configuring Trapping
Optional
Choose one or
more features as
required.
Configuring Secure MAC Addresses
Optional
Ignoring Authorization Information from the Server
Optional
Enabling Port Security
Configuration Prerequisites
Before enabling port security, you need to disable 802.1X and MAC authentication globally.
Configuration Procedure
Follow these steps to enable port security:
To do…
Use the command…
Remarks
Enter system view
system-view
—