114
Configuration procedure
To enable the MAC authentication critical voice VLAN feature on a port:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter Layer 2 Ethernet
interface view.
interface interface-type
interface-number
N/A
3.
Enable the MAC
authentication critical voice
VLAN feature on a port.
mac-authentication critical-voice
vlan
By default, the MAC
authentication critical voice VLAN
feature is disabled on the port.
Configuring the keep-online feature
By default, the device logs off online MAC authentication users if no server is reachable for MAC
reauthentication. The keep-online feature keeps authenticated MAC authentication users online
when no server is reachable for MAC reauthentication.
In a fast-recovery network, you can use the keep-online feature to prevent MAC authentication users
from coming online and going offline frequently.
To configure the keep-online feature:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter Layer 2 Ethernet
interface view.
interface
interface-type
interface-number
N/A
3.
Enable the keep-online feature
for authenticated MAC
authentication users on the
port.
mac-authentication
re-authenticate
server-unreachable keep-online
By default, the keep-online
feature is disabled.
This command takes effect only
when the authentication server
assigns reauthentication
attributes to the device.
Including user IP addresses in MAC
authentication requests
This feature enables the device to add user IP addresses to the MAC authentication requests that
are sent to an IMC server.
Upon receiving an authentication request, the IMC server compares the user IP and MAC addresses
in the request with its local IP-MAC mapping of the user. If a match is found, the IMC server verifies
the user valid. If no match is found, the user fails the MAC authentication. For information about IMC
user IP-MAC bindings, see
HPE IMC User Access Manager Administrator Guide
.
When you configure this feature, follow these guidelines and restrictions:
•
This feature takes effect only on MAC authentication users who use static IP addresses. Users
who obtain IP addresses through DHCP are not affected.