MAC Address Authentication Enhanced Function Configuration
273
c
CAUTION:
■
If more than one client are connected to a port, you cannot configure a Guest
VLAN for this port.
■
When a Guest VLAN is configured for a port, only one MAC address
authentication user can access the port. Even if you set the limit on the number
of MAC address authentication users to more than one, the configuration does
not take effect.
■
The undo vlan command cannot be used to remove the VLAN configured as a
Guest VLAN. If you want to remove this VLAN, you must remove the Guest
VLAN configuration for it. Refer to “VLAN Configuration” on page 77 for a
description of the undo VLAN command.
■
Only one Guest VLAN can be configured for a port, and the VLAN configured
as the Guest VLAN must be an existing VLAN. Otherwise, the Guest VLAN
configuration does not take effect. If you want to change the Guest VLAN for a
port, you must remove the current Guest VLAN and then configure a new
Guest VLAN for this port.
■
802.1x authentication cannot be enabled for a port configured with a Guest
VLAN.
■
The Guest VLAN function for MAC authentication does not take effect when
port security is enabled.
Configuring the
Maximum Number of
MAC Address
Authentication Users
Allowed to Access a Port
You can configure the maximum number of MAC address authentication users for
a port in order to control the maximum number of users accessing a port. After
the number of access users has exceeded the configured maximum number, the
switch will not trigger MAC address authentication for subsequent access users,
and thus these subsequent access users cannot access the network normally.
Configure the Guest VLAN for
the current port
mac-authentication
guest-vlan
vlan-id
Required
By default, no Guest VLAN is
configured for a port by
default.
Return to system view
quit
-
Configure the interval at which
the switch re-authenticates
users in Guest VLANs
mac-authentication timer
guest-vlan-reauth
interval
Optional
By default, the switch
re-authenticates the users in
Guest VLANs at the interval
of 30 seconds by default.
Table 206
Configure a Guest VLAN
Operation Command Description
Table 207
Configure the maximum number of MAC address authentication users allowed
to access a port
Operation
Command
Description
Enter system view
system-view
-
Enter Ethernet port view
interface
interface-type
interface-number
-
Summary of Contents for Switch 4210 9-Port
Page 22: ...20 CHAPTER 1 CLI CONFIGURATION ...
Page 74: ...72 CHAPTER 3 CONFIGURATION FILE MANAGEMENT ...
Page 84: ...82 CHAPTER 5 VLAN CONFIGURATION ...
Page 96: ...94 CHAPTER 8 IP PERFORMANCE CONFIGURATION ...
Page 108: ...106 CHAPTER 9 PORT BASIC CONFIGURATION ...
Page 122: ...120 CHAPTER 11 PORT ISOLATION CONFIGURATION ...
Page 140: ...138 CHAPTER 13 MAC ADDRESS TABLE MANAGEMENT ...
Page 234: ...232 CHAPTER 17 802 1X CONFIGURATION ...
Page 246: ...244 CHAPTER 20 AAA OVERVIEW ...
Page 270: ...268 CHAPTER 21 AAA CONFIGURATION ...
Page 292: ...290 CHAPTER 26 DHCP BOOTP CLIENT CONFIGURATION ...
Page 318: ...316 CHAPTER 29 MIRRORING CONFIGURATION ...
Page 340: ...338 CHAPTER 30 CLUSTER ...
Page 362: ...360 CHAPTER 33 SNMP CONFIGURATION ...
Page 368: ...366 CHAPTER 34 RMON CONFIGURATION ...
Page 450: ...448 CHAPTER 39 TFTP CONFIGURATION ...
Page 451: ......
Page 452: ...450 CHAPTER 39 TFTP CONFIGURATION ...
Page 470: ...468 CHAPTER 40 INFORMATION CENTER ...
Page 496: ...494 CHAPTER 44 DEVICE MANAGEMENT ...