110
Table 13
Relationships of the MAC authentication critical VLAN with other security features
Feature Relationship
description Reference
Quiet feature of MAC
authentication
The MAC authentication critical VLAN feature has
higher priority.
When a user fails MAC authentication because no
RADIUS authentication server is reachable, the user
can access the resources in the critical VLAN. The
user's MAC address is not marked as a silent MAC
address.
."
Port intrusion protection
The critical VLAN feature has higher priority than
the block MAC action but lower priority than the
shutdown port action of the port intrusion
protection feature.
."
To configure the MAC authentication critical VLAN on a port:
Step Command Remarks
1.
Enter system view.
system-view
N/A
2.
Enter Layer 2 Ethernet
interface view.
interface
interface-type
interface-number
N/A
3.
Specify the MAC
authentication critical
VLAN on the port.
mac-authentication critical vlan
critical-vlan-id
By default, no MAC authentication
critical VLAN is configured.
You can configure only one MAC
authentication critical VLAN on a
port.
Configuring the keep-online feature
By default, the device logs off online MAC authentication users if no server is reachable for MAC
reauthentication. The keep-online feature keeps authenticated MAC authentication users online when no
server is reachable for MAC reauthentication.
In a fast-recovery network, you can use the keep-online feature to prevent MAC authentication users from
coming online and going offline frequently.
To configure the keep-online feature:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter Layer 2 Ethernet interface
view.
interface
interface-type
interface-number
N/A
3.
Enable the keep-online feature
for authenticated MAC
authentication users on the port.
mac-authentication re-authenticate
server-unreachable keep-online
By default, the keep-online
feature is disabled.
This command takes effect only
when the authentication server
assigns reauthentication
attributes to the device.