1-9
To do…
Use the command…
Remarks
Enter system view
system-view
—
Set the interval at which the
switch triggers MAC address
authentication after a port is
added to the guest VLAN
port-security timer
guest-vlan-reauth interval
Optional
Enter Ethernet port view
interface
interface-type
interface-number
—
Set the security mode to
macAddressOrUserLoginSe
cure
port-security port-mode
userlogin-secure-or-mac
Required
Specify a VLAN as the guest
VLAN of the port
port-security guest-vlan vlan-id
Required
Note that:
z
Only an existing VLAN can be specified as a guest VLAN. Make sure the guest VLAN of a port
contain the resources that the users need.
z
If one user of the port has passed or is undergoing authentication, you cannot specify a guest
VLAN for it.
z
When a user using a port with a guest VLAN specified fail the authentication, the port is added to
the guest VLAN.
z
Multiple users may connect to one port in the
macAddressOrUserLoginSecure
mode for
authentication; however, after a guest VLAN is specified for the port, only one user can pass the
security authentication. In this case, the authentication client software of the other 802.1x users
displays messages about the failure; MAC address authentication does not have any client
software and therefore no such messages will be displayed.
z
To change the security mode from
macAddressOrUserLoginSecure
mode of a port that is
assigned to a guest VLAN, execute the
undo port-security guest-vlan
command first to remove
the guest VLAN configuration.
z
For a port configured with both the
port-security guest-vlan
and
port-security intrusion-mode
disableport
commands, when authentication of a user fails, only the intrusion detection feature is
triggered. The port is not added to the specified guest VLAN.
z
It is not recommended to configure the
port-security guest-vlan
and
port-security
intrusion-mode blockmac
commands simultaneously for a port. Because when the
authentication of a user fails, the blocking MAC address feature will be triggered and packets of the
user will be dropped, making the user unable to access the guest VLAN.
Ignoring the Authorization Information from the RADIUS Server
After an 802.1x user or MAC-authenticated user passes Remote Authentication Dial-In User Service
(RADIUS) authentication, the RADIUS server delivers the authorization information to the device. You
can configure a port to ignore the authorization information from the RADIUS server.
Follow these steps to configure a port to ignore the authorization information from the RADIUS server:
To do...
Use the command...
Remarks
Enter system view
system-view
—
Summary of Contents for S3100 Series
Page 74: ...7 7 Sysname ip http acl 2030...
Page 270: ...1 51 Sysname GigabitEthernet1 0 1 port trunk permit vlan all...
Page 579: ...ii Configuration Example 2 4 QoS Profile Configuration Example 2 4...
Page 713: ...1 22 Total associations 1...
Page 823: ...1 16...
Page 1054: ...i Table of Contents Appendix A Acronyms A 1...