1-4
z
Currently, port security supports two authentication methods: 802.1X and MAC authentication.
Different port security modes employ different authentication methods or different combinations of
authentication methods.
z
The maximum number of users a port supports is the lesser of the maximum number of secure
MAC addresses or the maximum number of authenticated users the security mode supports. For
example, in userLoginSecureExt mode, the maximum number of users a port supports is the lesser
of the maximum number of secure MAC addresses configured or the maximum number of users
that 802.1X supports.
z
Static MAC addresses are configured by using the
mac-address static
command. For details,
refer to
MAC Address Table Commands
in the
System Volume
.
These security mode naming rules may help you remember the modes:
z
userLogin
specifies port-based 802.1X authentication.
z
macAddress
specifies MAC address authentication.
z
Else
specifies that the authentication method before
Else
is applied first. If the authentication fails,
the protocol type of the authentication request determines whether to turn to the authentication
method following the
Else
.
z
In a security mode with
Or
, the protocol type of the authentication request determines which
authentication method is to be used.
z
userLogin
with
Secure
specifies MAC-based 802.1X authentication.
z
Ext
indicates allowing multiple 802.1X users to be authenticated and get online. A security mode
without
Ext
allows only one 802.1X user to be authenticated and get online.
Support for Guest VLAN and Auth-Fail VLAN
An 802.1X guest VLAN is the VLAN that a user is in before initiating authentication. An 802.1X Auth-Fail
VLAN is the VLAN that a user is in after failing authentication.
For a security mode that supports 802.1X authentication, you can configure a MAC-based guest VLAN
(802.1X MGV) or a MAC-based Auth-Fail VLAN (MAFV). For details about 802.1X MGV and MAFV,
refer to
802.1X Configuration
in the
Security Volume
.
Содержание S7906E - Switch
Страница 82: ...1 4 DeviceA interface tunnel 1 DeviceA Tunnel1 service loopback group 1...
Страница 200: ...1 11 DeviceB display vlan dynamic No dynamic vlans exist...
Страница 494: ...ii Displaying and Maintaining Tunneling Configuration 1 45 Troubleshooting Tunneling Configuration 1 45...
Страница 598: ...ii...
Страница 1757: ...4 9...
Страница 1770: ...6 4...
Страница 2017: ...2 11 Figure 2 3 SFTP client interface...
Страница 2062: ...i Table of Contents 1 URPF Configuration 1 1 URPF Overview 1 1 What is URPF 1 1 How URPF Works 1 1 Configuring URPF 1 2...
Страница 2238: ...1 16 DeviceA cfd linktrace service instance 1 mep 1001 target mep 4002...
Страница 2442: ...2 4 Set the interval for sending Syslog or trap messages to 20 seconds Device mac address information interval 20...