![Nortel 2526T Configuration Download Page 28](http://html1.mh-extra.com/html/nortel/2526t/2526t_configuration_1707291028.webp)
28
Using security in your network
SNMP trap support
With SNMP management, you can configure SNMP traps (on individual
ports) to generate automatically for conditions such as an unauthorized
access attempt or changes in port operating status.
The Nortel Ethernet Routing Switch 2500 Series supports both
industry-standard SNMP traps, as well as private Nortel enterprise traps.
Advanced EAPOL features
EAPOL supports the following advanced features:
•
Multihost (MH) support:
— Multiple Host with Multiple Authentication (MHMA) (see Multiple
Host with Multiple Authentication)
— Non-EAP hosts on EAP-enabled ports (see Non-EAP hosts on
EAP-enabled ports)
— Multiple Host with Single Authentication (MHSA) (see Multiple Host
with Single Authentication)
Multiple Host with Multiple Authentication
For an EAP-enabled port configured for Multiple Host with Multiple
Authentication (MHMA), a finite number of EAP users or devices with unique
MAC addresses are allowed on the port.
Each user must complete EAP authentication before the port allows traffic
from the corresponding MAC address. Only traffic from the authorized hosts
is allowed on that port.
Radius-assigned VLAN values are allowed in the MHMA mode. For
information about Radius-assigned VLANs in the MHMA mode, see
Radius-assigned VLAN use in MHMA mode.
MHMA support is on a per-port basis for an EAP-enabled port.
The following are some of the concepts associated with MHMA:
•
Logical and physical ports
Each unique port and MAC address combination is treated as a logical
port. MAX_MAC_PER_PORT defines the maximum number of MAC
addresses that can perform EAP authentication on a port at any given
time. Each logical port is treated as if it is in the SHSA mode.
•
Indexing for MIBs
Logical ports are indexed by a port and source MAC address
(src-mac) combination. Enterprise-specific MIBs are defined for state
machine-related MIB information for individual MACs.
•
Transmitting EAPOL packets
Nortel Ethernet Routing Switch 2500 Series
Security — Configuration and Management
NN47215-505 (323165-B)
02.01
Standard
4.1
19 November 2007
Copyright © 2007, Nortel Networks
.
Summary of Contents for 2526T
Page 227: ......