41-9
Catalyst 6500 Series Switch Software Configuration Guide—Release 8.7
OL-8978-04
Chapter 41 Configuring MAC Authentication Bypass
Configuring MAC Authentication Bypass
Enabling or Disabling Reauthentication
Enabling the global
set mac-auth-bypass re-authentication
command returns all MAC authentication
bypass values to their defaults. The default is disabled.
To enable or disable MAC authentication bypass reauthentication globally, perform this task in
privileged mode:
This example shows how to enable MAC authentication bypass reauthentication globally:
Console> (enable)
set mac-auth-bypass reauthentication enable
Global reauthentication mode enabled.
Console> (enable)
Specifying the Security Violation Mode
If there is a security violation on a port, the port goes into restricted mode or is shut down. In restricted
mode, the MAC address that causes the security violation is added as a trap entry into the forwarding
table. The default is shutdown.
To specify the security violation mode globally, perform this task in privileged mode:
This example shows how to specify “restricted” for the security violation mode:
Console> (enable)
set mac-auth-bypass violation restrict
Mac-Auth-Bypass security violation mode set to restrict.
Console> (enable)
Enabling or Disabling MAC Authentication Bypass RADIUS Accounting
The default is disabled. To enable or disable MAC authentication bypass RADIUS accounting, perform
these tasks in privileged mode:
Task
Command
Enable or disable MAC authentication bypass
reauthentication globally.
set mac-auth-bypass reauthentication
{
disable
|
enable
}
Task
Command
Specify the security violation mode globally.
set mac-auth-bypass violation
{
restrict
|
shutdown
}
Task
Command
Enable or disable MAC authentication bypass RADIUS
accounting.
set mac-auth-bypass
radius-accounting
{
disable
|
enable
}
Verify the MAC authentication bypass RADIUS
accounting state.
show mac-auth-bypass config