108
Specifying a MAC authentication domain
By default, MAC authentication users are in the system default authentication domain. To implement
different access policies for users, you can specify authentication domains for MAC authentication users
in the following ways:
•
Specify a global authentication domain in system view. This domain setting applies to all ports.
•
Specify an authentication domain for an individual port in Ethernet interface view.
MAC authentication chooses an authentication domain for users on a port in this order: the
interface-specific domain, the global domain, and the default domain. For more information about
authentication domains, see "
."
To specify an authentication domain for MAC authentication users:
Step Command Remarks
1.
Enter system view.
system-view
N/A
2.
Specify an authentication
domain for MAC
authentication users.
•
In system view:
mac-authentication domain
domain-name
•
In interface view:
a.
interface
interface-type
interface-number
b.
mac-authentication domain
domain-name
Use either method.
By default, the system default
authentication domain is used for
MAC authentication users.
Configuring a MAC authentication guest VLAN
Follow the guidelines in
when configuring a MAC authentication guest VLAN on a port.
Table 10
Relationships of the MAC authentication guest VLAN with other security features
Feature Relationship
description Reference
Quiet function of MAC
authentication
The MAC authentication guest VLAN
function has higher priority. A user can
access any resources in the guest VLAN.
"
Super VLAN
You cannot specify a VLAN as both a super
VLAN and a MAC authentication guest
VLAN.
See
Layer 2
—
LAN Switching
Configuration Guide
Port intrusion protection
The MAC authentication guest VLAN
function has higher priority than the block
MAC action but lower priority than the
shutdown port action of the port intrusion
protection feature.
802.1X guest VLAN on a
port that performs
MAC-based access
control
The MAC authentication guest VLAN has a
lower priority.