212
Syntax
mac-authentication carry user-ip
undo mac-authentication carry user-ip
Default
A MAC authentication request does not include the user IP address.
Views
Layer 2 Ethernet interface view
Layer 2 aggregate interface view
Predefined user roles
network-admin
mdc-admin
Usage guidelines
This command solves the IP conflict issue which might be caused by users' IP address modification.
After you configure this command, users cannot pass MAC authentication if the IP and MAC
information in the authentication requests do not match the users' IP-MAC mappings on the IMC
server.
The IMC server selects the IP-MAC combination for a MAC authentication user to match in the
following order:
1.
The IP and MAC addresses in the IMC platform user account associated with the MAC
authentication user.
2.
The IP and MAC addresses that are included in the authentication request. If the server does
not have an authenticated IP-MAC record for the user, it determines that the IP-MAC
combination of the user is valid. The server will record the IP-MAC combination of the user. If
the user IP address is changed at the next authentication, the user cannot pass authentication.
This command takes effect only on MAC authentication users that use static IP addresses. Users
that obtain IP addresses through DHCP are not affected.
Do not configure this command together with the
mac-authentication guest-vlan
or
mac-authentication guest-vsi
command on a port. Otherwise, users in the MAC authentication
guest VLAN or VSI cannot perform a new round of authentication.
Examples
# Include user IP addresses in MAC authentication requests on Ten-GigabitEthernet 1/0/1.
<Sysname> system-view
[Sysname] interface ten-gigabitethernet 1/0/1
[Sysname-Ten-GigabitEthernet1/0/1] mac-authentication carry user-ip
Related commands
mac-authentication
mac-authentication critical vlan
Use
mac-authentication critical vlan
to configure a MAC authentication critical VLAN on a port.
Use
undo mac-authentication critical vlan
to restore the default.
Syntax
mac-authentication critical vlan critical-vlan-id
undo mac-authentication critical vlan