data:image/s3,"s3://crabby-images/1bc15/1bc15a83f74266179a7a7527bce0837aa50634d9" alt="Cisco 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion Скачать руководство пользователя страница 359"
17-15
Catalyst 6500 Series Switch and Cisco 7600 Series Router Firewall Services Module Configuration Guide using ASDM
OL-20748-01
Chapter 17 Applying AAA for Network Access
Using MAC Addresses to Exempt Traffic from Authentication and Authorization
Where
id
is the string identifying the MAC list containing the MAC addresses whose traffic is to be
exempt from authentication and authorization. You can only enter one instance of the
aaa mac-exempt
command.
The following example bypasses authentication for a single MAC address:
hostname(config)#
mac-list abc permit 00a0.c95d.0282 ffff.ffff.ffff
hostname(config)#
aaa mac-exempt match abc
The following entry bypasses authentication for all Cisco IP Phones, which have the hardware ID
0003.E3:
hostname(config)#
mac-list acd permit 0003.E300.0000 FFFF.FF00.0000
hostname(config)#
aaa mac-exempt match acd
The following example bypasses authentication for a a group of MAC addresses except for
00a0.c95d.02b2. Enter the
deny
statement before the
permit
statement, because 00a0.c95d.02b2
matches the
permit
statement as well, and if it is first, the
deny
statement will never be matched.
hostname(config)#
mac-list 1 deny 00a0.c95d.0282 ffff.ffff.ffff
hostname(config)#
mac-list 1 permit 00a0.c95d.0000 ffff.ffff.0000
hostname(config)#
aaa mac-exempt match 1
Содержание 6500 - Catalyst Series 10 Gigabit EN Interface Module Expansion
Страница 35: ...P A R T 1 Getting Started and General Information ...
Страница 36: ......
Страница 297: ...P A R T 2 Configuring the Security Policy ...
Страница 298: ......
Страница 521: ...P A R T 3 System Administration ...
Страница 522: ......
Страница 613: ...P A R T 4 Reference ...
Страница 614: ......