
1-4
macAddressElseUs
erLoginSecureExt
This mode is similar to the
macAddressElseUserLoginSecure
mode,
except that there can be more than one
802.1x-authenticated user on the port.
macAddressAndUs
erLoginSecure
In this mode, a port firstly performs MAC
authentication for a user and then performs
802.1x authentication for the user if the user
passes MAC authentication. The user can
access the network after passing the two
authentications.
In this mode, up to one user can access the
network.
macAddressAndUs
erLoginSecureExt
This mode is similar to the
macAddressAndUserLoginSecure
mode,
except that more than one user can access
the network.
z
When the port operates in the
userlogin-withoui
mode, Intrusion Protection will not be triggered
even if the OUI address does not match.
z
On a port operating in either the
macAddressElseUserLoginSecure
mode or the
macAddressElseUserLoginSecureExt
mode, Intrusion Protection is triggered only after both
MAC-based authentication and 802.1x authentication on the same packet fail.
Port Security Configuration Task List
Complete the following tasks to configure port security:
Task
Remarks
Enabling Port Security
Required
Setting the Maximum Number of MAC Addresses Allowed on a
Port
Optional
Setting the Port Security Mode
Required
Configuring the NTK feature
Configuring intrusion protection
Configuring Port
Security
Features
Configuring the Trap feature
Optional
Choose one or more features
as required.
Ignoring the Authorization Information from the RADIUS Server
Optional
Configuring Security MAC Addresses
Optional
Enabling Port Security
Configuration Prerequisites
Before enabling port security, you need to disable 802.1x and MAC authentication globally.
Summary of Contents for H3C S5100-SI
Page 129: ...1 10...
Page 522: ...ii...
Page 701: ...3 2...
Page 797: ...1 20 0 00 packet loss round trip min avg max 50 60 70 ms...
Page 827: ...i Table of Contents 1 Acronyms 1 1...