
C
HAPTER
7
| Security Measures
Network Access (MAC Address Authentication)
– 205 –
C
ONFIGURING
N
ETWORK
A
CCESS
FOR
P
ORTS
Use the Security > Network Access > Port Configuration page to configure
MAC authentication on switch ports, including enabling address
authentication, setting the maximum MAC count, and enabling dynamic
VLAN or dynamic QoS assignments.
CLI R
EFERENCES
"Network Access (MAC Address Authentication)" on page 605
P
ARAMETERS
These parameters are displayed:
Mode
– Enables MAC authentication on a port. (Default: disabled)
Max MAC Count
– Sets the maximum number of MAC addresses that
can be authenticated on a port via MAC authentication; that is, the
Network Access process described in this section. (Range: 1-2048;
Default: 2048)
The maximum number of MAC addresses per port is 2048, and the
maximum number of secure MAC addresses supported for the switch
system is 2048. When the limit is reached, all new MAC addresses are
treated as authentication failures.
Guest VLAN
– Specifies the VLAN to be assigned to the port when
802.1X Authentication fails. (Range: 0-4094, where 0 means disabled;
Default: disabled)
The VLAN must already be created and active (see
). Also, when used with 802.1X authentication, intrusion action
must be set for “Guest VLAN” (see
"Configuring Authenticator Port
MAC Filter ID
– Allows a MAC Filter to be assigned to the port. MAC
addresses or MAC address ranges present in a selected MAC Filter are
exempt from authentication on the specified port (as described under
"Configuring a MAC Address Filter"
). (Range: 1-64; Default: None)
Dynamic VLAN
– Enables dynamic VLAN assignment for an
authenticated port. When enabled, any VLAN identifiers returned by the
RADIUS server are applied to the port, providing the VLANs have
already been created on the switch. (GVRP is not used to create the
VLANs.) (Default: Enabled)
The VLAN settings specified by the first authenticated MAC address are
implemented for a port. Other authenticated MAC addresses on the
port must have the same VLAN configuration, or they are treated as
authentication failures.
If dynamic VLAN assignment is enabled on a port and the RADIUS
server returns no VLAN configuration, the authentication is still treated
as a success, and the host is assigned to the default untagged VLAN.
When the dynamic VLAN assignment status is changed on a port, all
authenticated addresses are cleared from the secure MAC address
table.
Summary of Contents for DG-FS4528P
Page 2: ......
Page 4: ......
Page 148: ...CHAPTER 5 Simple Network Management Protocol Configuring SNMPv3 Groups 148 ...
Page 389: ...CHAPTER 17 VoIP Traffic Configuration Configuring Telephony OUI 389 ...
Page 515: ...CHAPTER 22 System Management Commands UPnP 515 TTL 20 Console ...
Page 972: ......
Page 973: ...DG FS4528P ...