![HP HP ProCurve Series 6600 Access Security Manual Download Page 661](http://html.mh-extra.com/html/hp/hp-procurve-series-6600/hp-procurve-series-6600_access-security-manual_163101661.webp)
13-49
Configuring Port-Based and User-Based Access Control (802.1X)
Option For Authenticator Ports: Configure Port-Security To Allow Only 802.1X-Authenticated Devices
Figure 13-9. Port-Access Support for Port-Security Operation
Port-Security
N o t e
If 802.1X port-access is configured on a given port, then port-security
learn-
mode
for that port must be set to either
continuous
(the default) or
port-access
.
In addition to the above, to use port-security on an authenticator port (chapter
14), use the per-port
client-limit
option to control how many MAC addresses
of 802.1X-authenticated devices the port is allowed to learn. (Using
client-limit
sets 802.1X to user-based operation on the specified ports.) When this limit is
reached, no further devices can be authenticated until a currently authenti-
cated device disconnects and the current delay period or logoff period has
expired.
Configure the port access type.
HP Switch(config)# aaa port-access authenticator a10 control auto
HP Switch(config)# show port-access authenticator a10 config
Port Access Authenticator Configuration
Port-access authenticator activated [No] : Yes
Allow RADIUS-assigned dynamic (GVRP) VLANs [No] : No
| Re-auth Access Max Quiet TX Supplicant Server Cntrl
Port | Period Control Reqs Period Timeout Timeout Timeout Dir
---- + ------- -------- ----- ------- -------- ---------- -------- -----
A10 | No Auto 2 60 30 30 30 both
Control mode
required for Port-
Security Support
Syntax:
aaa port-access authenticator <
port-list
> client-limit < 1 - 32 >
Configures user-based 802.1X authentication on the
specified ports and sets the number of authenticated
devices the port is allowed to learn. For more on this
command, refer to “Configuring Switch Ports as 802.1X
Authenticators” on page 13-17.)
— Or —
no aaa port-access authenticator <
port-list
> client-limit
Configures port-based 802.1X authentication on the
specified ports, which opens the port. (Refer to “User
Authentication Methods” on page 13-2.)
Summary of Contents for HP ProCurve Series 6600
Page 2: ......
Page 6: ...iv ...
Page 26: ...xxiv ...
Page 102: ...2 48 Configuring Username and Password Security Password Recovery ...
Page 204: ...4 72 Web and MAC Authentication Client Status ...
Page 550: ...10 130 IPv4 Access Control Lists ACLs General ACL Operating Notes ...
Page 612: ...12 24 Traffic Security Filters and Monitors Configuring Traffic Security Filters ...
Page 734: ...14 44 Configuring and Monitoring Port Security Operating Notes for Port Security ...
Page 756: ...16 8 Key Management System Configuring Key Chain Management ...
Page 776: ...20 Index web server proxy 14 42 webagent access 6 6 wildcard See ACL wildcard See ACL ...
Page 777: ......