Centralized MAC Address Authentication Configuration
197
■
Server-timeout timer. If the connection between a switch and a RADIUS server
times out when the switch authenticates a user on one of its ports, the switch
turns down the user. You can use the server-timeout timer to set the time out
time.
■
Table 177 lists the operations to set centralized MAC address authentication
timers.
Displaying and
Debugging Centralized
MAC Address
Authentication
You can display and verify centralized MAC address authentication-related
configuration by executing the
display
command in any view.
Centralized MAC
Address Authentication
Configuration Example
The configuration of centralized MAC address authentication is the same as that of
802.1x in this example except that:
■
Centralized MAC address authentication is enabled both globally and for the
ports.
■
For MAC address mode, the user name and password of a user to be
authenticated locally need to be configured as the MAC address of the user.
■
For MAC address mode, the user name and password of a user to be
authenticated by a RADIUS server need to be configured as the MAC address of
the user on the RADIUS server.
The following example describes how to enable port-based and global centralized
MAC address authentication, and local user configuration.
1
Enable centralized MAC address authentication on GigabitEthernet1/0/2 port.
<S5500> system-view
[S5500] mac-authentication interface GigabitEthernet 1/0/2
2
Configure centralized MAC address authentication mode to be MAC address mode.
[S5500] mac-authentication authmode usernameasmacaddress
3
Add a local access user.
a
Configure the user name and password for the local user.
[S5500] local-user 00-e0-fc-01-01-01
[S5500-luser-00-e0-fc-01-01-01] password simple 00-e0-fc-01-01-01
b
Set service type to LAN-access for the local user.
[S5500-luser-00-e0-fc-01-01-01] service-type lan-access
Table 177
Set a centralized MAC address authentication timer
Operation
Command
Description
Enter system view
system-view
Set a centralized MAC
address authentication
timer
mac-authentication
timer
{
offline-detect
offline-detect-value
|
quiet
quiet-value
|
server-timeout
server-timeout-value
}
Optional
By default, the three MAC address
authentication timers are set as
follows:
Offline-detect timer: 300 seconds
Quiet timer: 1 minute
Server-timeout timer: 100 seconds
Table 178
Display and debug centralized MAC address authentication
Operation
Command
Description
Display global information
about centralized MAC address
authentication
display
mac-authentication
[
interface
interface-list
]
Optional
You can execute the
display
command in any view.
Summary of Contents for 5500 SI - Switch - Stackable
Page 24: ...24 ABOUT THIS GUIDE...
Page 50: ...50 CHAPTER 1 GETTING STARTED...
Page 54: ...54 CHAPTER 2 ADDRESS MANAGEMENT CONFIGURATION...
Page 78: ...78 CHAPTER 3 PORT OPERATION...
Page 88: ...88 CHAPTER 4 XRN CONFIGURATION...
Page 122: ...122 CHAPTER 8 VLAN VPN CONFIGURATION...
Page 216: ...216 CHAPTER 15 SSH TERMINAL SERVICES...
Page 268: ...268 CHAPTER 16 IP ROUTING PROTOCOL OPERATION...
Page 308: ...308 CHAPTER 17 NETWORK PROTOCOL OPERATION...
Page 349: ...349...
Page 350: ...350 CHAPTER 18 MULTICAST PROTOCOL...
Page 522: ...522 CHAPTER 22 FILE SYSTEM MANAGEMENT...
Page 584: ...584 CHAPTER 30 PASSWORD CONTROL CONFIGURATION OPERATIONS...
Page 600: ...600 CHAPTER 31 MSDP CONFIGURATION...
Page 614: ...614 CHAPTER 32 CLUSTERING...
Page 670: ...670 CHAPTER C AUTHENTICATING THE SWITCH 5500 WITH CISCO SECURE ACS...