112
# After a user passes MAC authentication, use
display connection
to display online user information.
<Router> display connection
Index=29 ,Username=aaa@2000
MAC=00e0-fc12-3456
IP=N/A
IPv6=N/A
Total 1 connection(s) matched.
ACL assignment configuration example
Network requirements
As shown in
, a host connects to port GigabitEthernet 1/0/1 on an access device and the
device uses RADIUS servers to perform authentication, authorization, and accounting.
Perform MAC authentication on port GigabitEthernet 1/0/1 to control Internet access. Make sure that
an authenticated user can access the Internet but the FTP server at 10.0.0.1.
Use MAC-based user accounts for MAC authentication users. The MAC addresses are separated by
hyphens and in lower case.
Figure 42
ACL assignment
Check that the RADIUS server and the access device can reach each other.
Configuration procedure
1.
Configure the ACL assignment.
# Configure ACL 3000 to deny packets destined for 10.0.0.1.
<Sysname> system-view
[Sysname] acl number 3000
[Sysname-acl-adv-3000] rule 0 deny ip destination 10.0.0.1 0
[Sysname-acl-adv-3000] quit