PowerConnect B-Series FCX Configuration Guide
1291
53-1002266-01
Displaying multi-device port authentication information
36
Multi-device port authentication password override
The multi-device port authentication feature communicates with the RADIUS server to authenticate
a newly found MAC address. The RADIUS server is configured with the usernames and passwords
of authenticated users. For multi-device port authentication, the username and password is the
MAC address itself; that is, the device uses the MAC address for both the username and the
password in the request sent to the RADIUS server. For example, given a MAC address of
0007e90feaa1, the users file on the RADIUS server would be configured with a username and
password both set to 0007e90feaa1. When traffic from this MAC address is encountered on a
MAC-authentication-enabled interface, the device sends the RADIUS server an Access-Request
message with 0007e90feaa1 as both the username and password.
The MAC address is the
default
password for multi-device port authentication, and you can
optionally configure the device to use a different password. Note that the MAC address is still the
username and cannot be changed.
To change the password for multi-device port authentication, enter a command such as the
following at the GLOBAL Config Level of the CLI.
PowerConnect(config)#mac-authentication password-override
Syntax: [no] mac-authentication password-override
<password>
where
<password>
can have up to 32 alphanumeric characters, but cannot include blank spaces.
Limiting the number of authenticated MAC addresses
You cannot enable MAC port security on the same port that has multi-device port authentication
enabled. To simulate the function of MAC port security, you can enter a command such as the
following.
PowerConnect(config-if-e1000-2)#mac-authentication max-accepted-session 5
Syntax: [no] mac-authentication max-accepted-session
<session-number>
This command limits the number of successfully authenticated MAC addresses. Enter a value from
1 - 250 for session-number
Displaying multi-device port authentication information
You can display the following information about the multi-device port authentication configuration:
•
Information about authenticated MAC addresses
•
Information about the multi-device port authentication configuration
•
Authentication Information for a specific MAC address or port
•
Multi-device port authentication settings and authenticated MAC addresses for each port
where the multi-device port authentication feature is enabled
•
The MAC addresses that have been successfully authenticated
•
The MAC addresses for which authentication was not successful
Summary of Contents for PowerConnect B-FCXs
Page 1: ...53 1002266 01 18 March 2011 PowerConnect B Series FCX Configuration Guide ...
Page 248: ...206 PowerConnect B Series FCX Configuration Guide 53 1002266 01 IPv6 management commands 7 ...
Page 374: ...332 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Jumbo frame support 9 ...
Page 568: ...526 PowerConnect B Series FCX Configuration Guide 53 1002266 01 CLI examples 14 ...
Page 588: ...546 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Sample application 15 ...
Page 684: ...642 PowerConnect B Series FCX Configuration Guide 53 1002266 01 VLAN based mirroring 20 ...
Page 724: ...682 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Reading CDP packets 23 ...
Page 930: ...888 PowerConnect B Series FCX Configuration Guide 53 1002266 01 26 ...
Page 948: ...906 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Configuring MLD snooping 27 ...
Page 1348: ...1306 PowerConnect B Series FCX Configuration Guide 53 1002266 01 Example configurations 36 ...
Page 1406: ...1364 PowerConnect B Series FCX Configuration Guide 53 1002266 01 IP source guard 39 ...