227
Index : 2 Value : 123402
Index : 3 Value : 123403
Index : 4 Value : 123404
Index : 5 Value : 123405
Ten-GigabitEthernet1/0/1 is link-up
Port mode : userLoginWithOUI
NeedToKnow mode : Disabled
Intrusion protection mode : NoAction
Security MAC address attribute
Learning mode : Sticky
Aging type : Periodical
Max secure MAC addresses : Not configured
Current secure MAC addresses : 1
Authorization :Permitted
NAS-ID profile : Not configured
# Display information about the online 802.1X user to verify 802.1X configuration.
[Device] display dot1x
# Verify that the port also allows one user whose MAC address has an OUI among the specified
OUIs to pass authentication.
[Device] display mac-address interface ten-gigabitethernet 1/0/1
MAC Address VLAN ID State Port/NickName Aging
1234-0300-0011 1 Learned XGE1/0/1 Y
macAddressElseUserLoginSecure configuration example
Network requirements
As shown in
, a client is connected to the device through Ten-GigabitEthernet 1/0/1. The
device authenticates the client by a RADIUS server in ISP domain
sun
. If the authentication
succeeds, the client is authorized to access the Internet.
Configure Ten-GigabitEthernet 1/0/1
of the device to meet the following requirements:
•
Allow more than one MAC authenticated user to log on.
•
For 802.1X users, perform MAC authentication first and then, if MAC authentication fails,
802.1X authentication. Allow only one 802.1X user to log on.
•
Use the MAC address of each user as the username and password for authentication. A MAC
address is in the hexadecimal notation with hyphens, and letters are in upper case.
•
Set the total number of MAC authenticated users and 802.1X authenticated users to 64.
•
Enable NTK (
ntkonly
mode) to prevent frames from being sent to unknown MAC addresses.
Summary of Contents for FlexFabric 5940 SERIES
Page 251: ...238 ...