
C
HAPTER
13
| Security Measures
Network Access (MAC Address Authentication)
– 333 –
◆
If duplicate profiles are passed in the Filter-ID attribute, then only the
first profile is used.
For example, if the attribute is “service-policy-in=p1;service-policy-
in=p2”, then the switch applies only the DiffServ profile “p1.”
◆
Any unsupported profiles in the Filter-ID attribute are ignored.
For example, if the attribute is “map-ip-dscp=2:3;service-policy-
in=p1,” then the switch ignores the “map-ip-dscp” profile.
◆
When authentication is successful, the dynamic QoS information may
not be passed from the RADIUS server due to one of the following
conditions (authentication result remains unchanged):
■
The Filter-ID attribute cannot be found to carry the user profile.
■
The Filter-ID attribute is empty.
■
The Filter-ID attribute format for dynamic QoS assignment is
unrecognizable (can not recognize the whole Filter-ID attribute).
◆
Dynamic QoS assignment fails and the authentication result changes
from success to failure when the following conditions occur:
■
Illegal characters found in a profile value (for example, a non-digital
character in an 802.1p profile value).
■
Failure to configure the received profiles on the authenticated port.
◆
When the last user logs off on a port with a dynamic QoS assignment,
the switch restores the original QoS configuration for the port.
◆
When a user attempts to log into the network with a returned dynamic
QoS profile that is different from users already logged on to the same
port, the user is denied access.
◆
While a port has an assigned dynamic QoS profile, any manual QoS
configuration changes only take effect after all users have logged off
the port.
C
ONFIGURING
G
LOBAL
S
ETTINGS
FOR
N
ETWORK
A
CCESS
MAC address authentication is configured on a per-port basis, however
there are two configurable parameters that apply globally to all ports on
the switch. Use the Security > Network Access (Configure Global) page to
configure MAC address authentication aging and reauthentication time.
CLI R
EFERENCES
◆
"Network Access (MAC Address Authentication)" on page 895
P
ARAMETERS
These parameters are displayed:
◆
Aging Status
– Enables aging for authenticated MAC addresses stored
in the secure MAC address table. (Default: Disabled)
Summary of Contents for ECS4110-28T
Page 2: ......
Page 4: ......
Page 63: ...FIGURES 63 Figure 428 Configuring VLAN Translation 1177...
Page 64: ...FIGURES 64...
Page 72: ...TABLES 72...
Page 74: ...SECTION I Getting Started 74...
Page 102: ...SECTION II Web Configuration 102 General IP Routing on page 679...
Page 154: ...CHAPTER 4 Basic Management Tasks Resetting the System 154...
Page 198: ...CHAPTER 5 Interface Configuration VLAN Trunking 198 Figure 65 Configuring VLAN Trunking...
Page 272: ...CHAPTER 9 Congestion Control Automatic Traffic Control 272...
Page 286: ...CHAPTER 10 Class of Service Layer 3 4 Priority Settings 286...
Page 420: ...CHAPTER 13 Security Measures DHCP Snooping 420...
Page 566: ...CHAPTER 14 Basic Administration Protocols OAM Configuration 566...
Page 638: ...CHAPTER 15 Multicast Filtering Multicast VLAN Registration for IPv6 638...
Page 662: ...CHAPTER 16 IP Configuration Setting the Switch s IP Address IP Version 6 662...
Page 678: ...CHAPTER 17 IP Services Configuring the PPPoE Intermediate Agent 678...
Page 792: ...CHAPTER 21 System Management Commands Switch Clustering 792...
Page 822: ...CHAPTER 23 Remote Monitoring Commands 822...
Page 888: ...CHAPTER 24 Authentication Commands PPPoE Intermediate Agent 888...
Page 968: ...CHAPTER 25 General Security Measures Port based Traffic Segmentation 968...
Page 994: ...CHAPTER 26 Access Control Lists ACL Information 994...
Page 1034: ...CHAPTER 28 Link Aggregation Commands Trunk Status Display Commands 1034...
Page 1044: ...CHAPTER 29 Power over Ethernet Commands 1044...
Page 1084: ...CHAPTER 33 UniDirectional Link Detection Commands 1084...
Page 1090: ...CHAPTER 34 Address Table Commands 1090...
Page 1194: ...CHAPTER 37 VLAN Commands Configuring Voice VLANs 1194...
Page 1388: ...CHAPTER 42 CFM Commands Delay Measure Operations 1388...
Page 1410: ...CHAPTER 44 Domain Name Service Commands 1410...
Page 1420: ...CHAPTER 45 DHCP Commands DHCP Relay 1420...
Page 1472: ...CHAPTER 46 IP Routing Commands IPv4 Commands 1472...
Page 1474: ...SECTION IV Appendices 1474...
Page 1502: ...COMMAND LIST 1502...
Page 1513: ......
Page 1514: ...ECS4110 28T ECS4110 28P ECS4110 52T ECS4110 52P E072014 ST R02 150200000929A...