![Nortel 2526T Configuration Download Page 32](http://html1.mh-extra.com/html/nortel/2526t/2526t_configuration_1707291032.webp)
32
Using security in your network
The additional non-EAPOL hosts are counted as intruders. New EAPOL
hosts can continue to negotiate EAPOL authentication.
•
When the intruder count reaches 32, a SNMP trap and system log
message are generated. The port administrative status is set to
force-unauthorized, and you must reset the port administrative status
(from force-unauthorized to auto) to allow new EAPOL and non-EAPOL
negotiations on the port.
•
The feature uses enterprise-specific MIBs.
•
Configuration settings are saved across resets.
ATTENTION
Guest VLAN and non-EAPOL host support on a port are mutually exclusive.
If you have configured a port to support Guest VLAN, you cannot enable
support for non-EAPOL hosts on that port. Similarly, if you have configured an
EAPOL-enabled port to support non-EAPOL hosts, you cannot enable Guest
VLAN on that port. Also, you cannot enable non-EAPOL support on uplink or
call server ports.
For information about configuring non-EAPOL host support, see Configuring
support for non-EAPOL hosts on EAPOL-enabled ports.
Non-EAPOL MAC RADIUS authentication
For RADIUS authentication of a non-EAPOL host MAC address, the switch
generates a <username, password> pair as follows:
•
The username is the non-EAPOL MAC address in string format.
•
The password is a string that combines the MAC address, switch IP
address, unit, and port.
•
The password is a string that combines the MAC address, switch IP
address, unit, and port.
ATTENTION
Use only lowercase letters for usernames and passwords configured on the
Radius server.
Follow these global configuration examples, to select a password format that
combines one or more of these 3 elements:
password = 010010011253..0305 (when the switch IP address, unit and port
are used).
password = 010010011253.. (when only the switch IP address is used).
The following example illustrates the <username, password> pair format:
switch IP address = 10.10.11.253
Nortel Ethernet Routing Switch 2500 Series
Security — Configuration and Management
NN47215-505 (323165-B)
02.01
Standard
4.1
19 November 2007
Copyright © 2007, Nortel Networks
.
Summary of Contents for 2526T
Page 227: ......