General Security Measures
4-161
4
(MAC Address Authentication)
Network Access authentication controls access to the network by authenticating the
MAC address of each host that attempts to connect to a switch port. Traffic received
from a specific MAC address is forwarded by the switch only if the source MAC
address is successfully authenticated by a central RADIUS server. While
authentication for a MAC address is in progress, all traffic is blocked until
authentication is completed. On successful authentication, the RADIUS server may
optionally assign VLAN and QoS settings for the switch port.
Table 4-43 Network Access
Command
Function
Mode
Page
network-access aging
Enables MAC address aging
GC
4-162
network-access mac-filter
Adds a MAC address to a filter table
GC
4-162
network-access
port-mac-filter
Enables the specified MAC address filter
IC
4-163
network-access
max-mac-count
Sets a maximum number for authenticated MAC
addresses on an interface
IC
4-163
network-access mode
Enables MAC authentication on an interface
IC
4-164
mac-authentication
reauth-time
Sets the time period after which a connected MAC
address must be re-authenticated
GC
4-165
mac-authentication
max-mac-count
Sets a maximum number for mac-authentication
authenticated MAC addresses on an interface
IC
4-166
mac-authentication
intrusion-action
Determines the port response when a connected host fails
MAC authentication.
IC
4-166
network-access dynamic-vlan Enables dynamic VLAN assignment from a RADIUS
server
IC
4-167
network-access guest-vlan
Specifies the guest VLAN
IC
4-167
network-access dynamic-qos Enables the dynamic quality of service feature
IC
4-168
network-access
link-detection
Enables the link detection feature
IC
4-167
network-access
link-detection link-down
Configures the link detection feature to detect and act
upon link-down events
IC
4-167
network-access
link-detection link-up
Configures the link detection feature to detect and act
upon link-up events
IC
4-167
network-access
link-detection link-up-down
Configures the link detection feature to detect and act
upon both link-up and link-down events
IC
4-167
clear network-access
Clears authenticated MAC addresses from the address
table
PE
4-171
show network-access
Displays the MAC authentication settings for port
interfaces
PE
4-171
show network-access
mac-address-table
Displays information for entries in the secure MAC
address table
PE
4-172
show network-access
mac-filter
Displays information for entries in the MAC filter tables
PE
4-173
Summary of Contents for 6152PL2 FICHE
Page 2: ......
Page 6: ...vi ...
Page 8: ...viii ...
Page 32: ...Tables xxxii ...
Page 38: ...Figures xxxviii ...
Page 56: ...Initial Configuration 2 10 2 ...
Page 378: ...Configuring the Switch 3 322 3 ...
Page 817: ......