Command Manual – Port Security & Port Binding
Quidway S3900 Series Ethernet Switches-Release 1510
Chapter 1 Port Security Commands
Huawei Technologies Proprietary
1-13
Security
mode
Description
Feature
secure
In this mode, the system is disabled from learning
MAC addresses from this port.
Only the packets whose original MAC addresses
are the configured static MAC addresses can
pass the port.
userlogin
In this mode, port-based 802.1x authentication is
performed for connected users.
In this mode, the
NTK and
Intrusion
Protection
features are not
enabled.
userlogin-
secure
The port is enabled only after the access user
passes the 802.1x authentication. Even after the
port is enabled, only the packets of the
successfully authenticated user can pass through
the port.
In this mode, only one 802.1x-authenticated user
is allowed to access the port.
When the port changes from the normal mode to
this security mode, the system automatically
removes the existing dynamic MAC address
entries and authenticated MAC address entries
on the port.
userlogin-
withoui
This mode is similar to the
userlogin-secure
mode, except that there can be one OUI-carrying
MAC address being successfully authenticated in
addition to the single 802.1x-authenticated user
who is allowed to access the port.
When the port changes from the normal mode to
this security mode, the system automatically
removes the existing dynamic/authenticated MAC
address entries on the port.
mac-authe
ntication
In this mode, MAC address–based authentication
is performed for access users.
userlogin-
secure-or-
mac
In this mode, the two kinds of authentication in
mac-authentication
and
userlogin-secure
modes can be performed simultaneously. If both
kinds of authentication succeed, the
userlogin-secure
mode takes precedence over
the
mac-authentication
mode.
userlogin-
secure-els
e-mac
In this mode, first the MAC-based authentication
is performed. If this authentication succeeds, the
mac-authentication
mode is adopted, or else,
the authentication in
userlogin-secure
mode is
performed.
userlogin-
secure-ext
This mode is similar to the
userlogin-secure
mode, except that there can be more than one
802.1x-authenticated user on the port.
In these modes,
the device
enables the NTK
and Intrusion
Protection
features upon
detecting an
illegal packet.