107
Configuring MAC authentication on a port
To do…
Command…
Remarks
1.
Enter system view.
system-view
—
2.
Enable MAC
authenticatio
n.
In system view
mac-authentication
interface
interface-list
Required.
Disabled by default.
Enable MAC authentication for
ports in bulk in system view or
an individual port in interface
view.
In interface view
interface
interface-type interface-
number
mac-authentication
3.
Set the maximum number of
concurrent MAC authentication
users allowed on a port.
mac-authentication max-user
user-number
Optional.
By default, up to 1024
concurrent users are allowed
on a port.
NOTE:
•
You cannot enable MAC authentication on a link aggregation member port or a service loopback
port. If MAC authentication is enabled on a port, you cannot assign it to a link aggregation or
service loopback group.
•
Support for
mac-authentication max-user
depends on the device model.
Specifying MAC authentication user domain
By default, MAC authentication users are in the system default authentication domain. To implement
different access policies for users, specify authentication domains for MAC authentication users in the
following ways:
•
Specify a global authentication domain in system view. This domain setting applies to all ports.
•
Specify an authentication domain for an individual port in interface view.
MAC authentication chooses an authentication domain for users on a port in this order: the port-specific
domain, the global domain, and the default domain. For more information about authentication
domains, see "
To specify an authentication domain for MAC authentication users:
To do…
Command…
Remarks
1.
Enter system view.
system-view
—
2.
Specify an authentication
domain for MAC
authentication users.
mac-authentication domain
domain-
name
Required.
Use either approach.
By default, the system default
authentication domain is used for
MAC authentication users.
interface
interface-type interface-
number
mac-authentication domain
domain-
name