
1-3
On the port, if you want to…
Use the security mode…
Feature that
can be
triggered
These security mode naming rules may help you remember the modes:
z
userLogin
specifies 802.1X authentication and port-based access control.
z
macAddress
specifies MAC address authentication.
z
Else
specifies that the authentication method before
Else
is applied first. If the authentication fails, whether
to turn to the authentication method following
Else
depends on the protocol type of the authentication
request.
z
In a security mode with
Or
, which authentication method is to be used depends on the protocol type of the
authentication request. However, 802.1X authentication is preferred by wireless users.
z
userLogin
with
Secure
specifies 802.1X authentication and MAC-based access control.
z
Ext
indicates allowing multiple 802.1X users to be authenticated and serviced at the same time. A security
mode without
Ext
allows only one user to pass 802.1X authentication.
Control MAC address learning
A port in autoLearn or secure mode allows only frames sourced from the MAC addresses that are in the
MAC address table to pass.
1) autoLearn
A port in this mode can learn MAC addresses. These dynamically learned MAC addresses are secure
MAC addresses. You can also configure secure MAC addresses by using the
port-security
mac-address security
command. A secure MAC addresses never ages out by default. When the
number of secure MAC addresses reaches the upper limit, the port turns to secure mode. In addition,
you can configure MAC addresses manually by using the
mac-address dynamic
and
mac-address
static
commands for a port in autoLearn mode.
In autoLearn mode, dynamic MAC address learning function on the port in MAC address management
is disabled.
2) secure
In this mode, MAC address learning is disabled on the port and you can configure MAC addresses by
using the
mac-address static
and
mac-address dynamic
commands.
Perform 802.1X authentication
1) userLogin
A port in this mode performs 802.1X authentication and implements port-based access control. The port
can service multiple 802.1X users. If one 802.1X user passes authentication, all the other 802.1X users
of the port can access the network without authentication.
2) userLoginSecure
A port in this mode performs 802.1X authentication and implements MAC-based access control. The
port services only one user passing 802.1X authentication.
3) userLoginSecureExt
This mode is similar to the userLoginSecure mode except that this mode supports multiple online
802.1X users.
4) userLoginWithOUI
This mode is similar to the userLoginSecure mode. In addition, a
port in this mode also permits frames from
a user
whose MAC address contains a specified OUI (organizationally unique identifier).
z
For wired users, the port performs 802.1X authentication upon receiving 802.1X frames, and performs OUI
check upon receiving non-802.1X frames.
Summary of Contents for S5120-EI Series
Page 139: ...ii...
Page 578: ...1 21 C...
Page 739: ...1 12 Enable ARP detection based on 802 1X security entries SwitchB arp detection mode dot1x...
Page 926: ...2 8...
Page 942: ...ii Single Device Upgrade 3 4 IRF System Upgrade 3 5...
Page 985: ...1 1...
Page 1018: ...1 6...