DGS-1510/ME Series Metro Ethernet Switch CLI Reference Guide
356
If the port authorize mode is host based mode, then each user will be authorized individually and be capable of
getting its own assigned VLAN.
If port’s block time is set to” infinite”, it means that a failed authentication client will never be blocked. Block time
will be set to “0”.
Format
config mac_based_access_control ports [<portlist> | all] {state [enable | disable] | mode [port_based |
host_based] | aging_time [infinite | <min 1-1440>] | block_time <sec 0-300> | max_users [<value 1-1000> |
no_limit]}(1)
Parameters
<portlist>
- Enter a list of ports to be configured.
all
- Specifies all existed ports of switch for configuring the MAC-based Access Control function parameters.
state
- Specifies whether the port’s MAC-based Access Control function is enabled or disabled.
enable
- Specifies that the port's MAC-based Access Control states will be enabled.
disable
- Specifies that the port's MAC-based Access Control states will be disabled.
mode
- Specifies the MAC-based access control port mode used.
port_based
- Specifies that the MAC-based access control port mode will be set to port-based.
host_based
- Specifies that the MAC-based access control port mode will be set to host-based.
aging_time
- Specifies a time period during which an authenticated host will be kept in an authenticated state.
When the aging time has timed-out, the host will be moved back to unauthenticated state.
infinite
- Specifies that the authorized clients will not be aged out automatically.
<min 1-1440>
- Enter the aging time value here. This value must be between 1 and 1440 minutes.
block_time
- Specifies the block time. If a host fails to pass the authentication, the next authentication will not
start within the block time unless the user clears the entry state manually.
<sec 0-300>
-Enter the block time value here. This value must be between 0 and 300 seconds. If the block
time is set to 0, it means do not block the client that failed authentication.
max_users
- Specifies maximum number of users per port. The default value is 128.
<value 1-1000>
- Enter the maximum number of users per port here. This value must be between 1 and 1000.
no_limit
- Specifies to not limit the maximum number of users on the port.
Restrictions
Only Administrators, Operators and Power-Users can issue this command.
Example
To configure an unlimited number of maximum users for MAC-based Access Control on ports 1 to 8:
DGS-1510-28XMP/ME:admin# config mac_based_access_control ports 1-8 max_users no_limit
Command: config mac_based_access_control ports 1-8 max_users no_limit
Success.
DGS-1510-28XMP/ME:admin#
To configure the MAC-based Access Control timer parameters to have an infinite aging time and a block time of
120 seconds on ports 1 to 8:
Summary of Contents for DGS-1510/ME Series
Page 1: ......