107
MAC authentication can take effect on a port only when it is enabled globally and on the port.
Configuring MAC authentication globally
Step Command Remarks
1.
Enter system view.
system-view
N/A
2.
Enable MAC
authentication globally.
mac-authentication
Disabled by default.
3.
Configure MAC
authentication timers.
mac-authentication
timer
{
offline-detect
offline-detect-value
|
quiet
quiet-value
|
server-timeout
server-timeout-value
}
Optional.
By default, the offline detect timer is
300 seconds, the quiet timer is 60
seconds, and the server timeout
timer is 100 seconds.
4.
Configure the properties
of MAC authentication
user accounts.
mac-authentication user-name-format
{
fixed
[
account
name
] [
password
{
cipher
|
simple
}
password
]
|
mac-address
[ {
with-hyphen
|
without-hyphen
} [
lowercase
|
uppercase
] ] }
Optional.
By default, the username and
password for a MAC
authentication user account must
be a MAC address in lower case
without hyphens.
NOTE:
When global MAC authentication is enabled, the EAD fast deployment function cannot take effect.
Configuring MAC authentication on a port
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enable MAC authentication.
•
In system view:
mac-authentication
interface
interface-list
•
In interface view:
a.
interface
interface-type
interface-number
b.
mac-authentication
Disabled by default.
Enable MAC authentication for
ports in bulk in system view or an
individual port in Ethernet
interface view.
3.
Set the maximum number of
concurrent MAC authentication
users allowed on a port.
mac-authentication max-user
user-number
Optional.
By default, the maximum number
of concurrent MAC
authentication users is 2048.
NOTE:
You cannot add a MAC authentication enabled port in to a link aggregation group or service loopback
group, or enable MAC authentication on a port already in a link aggregation group or service loopback
group.