
218
Step Command Remarks
1.
Enter system view.
system-view
N/A
2.
Configure MAC
authentication timers.
mac-authentication
timer
{
offline-detect
offline-detect-value
|
quiet
quiet-value
|
server-timeout
server-timeout-value
}
By default, the offline detect
timer is 300 seconds, the quiet
timer is 60 seconds, and the
server timeout timer is 100
seconds.
Enabling MAC authentication offline detection
This feature logs a user out of the device if the device does not receive any packets from the user
within the offline detect timer. The device also requests to stop accounting for the user at the same
time. For more information about the offline detect timer, see "
Configuring MAC authentication
Disabling this feature disables the device from inspecting the online user status.
To enable MAC authentication offline detection:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter Ethernet interface view.
interface interface-type
interface-number
N/A
3.
Enable MAC authentication
offline detection.
mac-authentication
offline-detect enable
By default, MAC authentication
offline detection is enabled.
Setting the maximum number of concurrent MAC
authentication users on a port
Perform this task to prevent the system resources from being overused.
To set the maximum number of concurrent MAC authentication users on a port:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter interface view.
interface interface-type
interface-number
N/A
3.
Set the maximum number of
concurrent MAC
authentication users on the
port
mac-authentication max-user
max-number
The default setting is
4294967295.
Enabling MAC authentication multi-VLAN mode
on a port
The MAC authentication multi-VLAN mode prevents an authenticated online user from service
interruption caused by VLAN changes on a port. When the port receives a packet sourced from the
user in a VLAN not matching the existing MAC-VLAN mapping, the device neither logs off the user