41-10
Catalyst 6500 Series Switch Software Configuration Guide—Release 8.7
OL-8978-04
Chapter 41 Configuring MAC Authentication Bypass
Configuring MAC Authentication Bypass
This example shows how to enable MAC authentication bypass RADIUS accounting:
Console> (enable)
set mac-auth-bypass radius-accounting enable
Radius Accounting for MacAuth enabled.
Console> (enable)
This example shows how to verify the MAC authentication bypass RADIUS accounting state:
Console> (enable)
show mac-auth-bypass config
Mac-Auth-Bypass Global Config
-----------------------------
Mac-Auth-Bypass Status = Enabled
AuthFail Timeout = 60
RadiusAccounting = Enabled
Reauthentication = Disabled
Reauth Timeout = 3600
Shutdown Timeout = 60
Violation mode = Shutdown
Console> (enable)
Configuring a PVLAN on a MAC Authentication Bypass-Enabled Port
To configure a PVLAN on a MAC authentication bypass-enabled port, perform these tasks in enabled
mode:
This example shows how to configure MAC authentication bypass-enabled on PVLAN port 3/13:
Console> (enable)
set mac-auth-bypass enable
Mac-Auth-Bypass enabled globally.
Console> (enable)
set port mac-auth-bypass 3/13 enable
Mac-Auth-Bypass successfully enabled on port(s) 3/13
Console> (enable)
show port mac-auth-bypass 3/13
Port Mac-Auth-Bypass State MAC Address Auth-State Vlan
----- --------------------- ----------------- ----------------- -----
3/13 Enabled 00-00-00-00-00-00 waiting 25
Port Termination action Session Timeout Shutdown/Time-Left
----- ------------------ --------------- ------------------
3/13 initialize 3600 NO -
Port PolicyGroups
----- -----------------------------------------------------
3/13 -
Port Critical Critical-Status
----- -------- ---------------
3/13 Enabled -
Console> (enable)
set pvlan 12 30 3/13
Host mode set to enable for port 3/13.
BPDU guard set to enable for port 3/13.
Trunk mode set to off for ports 3/13
Task
Command
Configure MAC authentication bypass.
set mac-auth-bypass {enable | disable}
Configure a PVLAN on a MAC authentication
bypass-enabled port.
set port mac-auth-bypass
mod/port
{enable |
disable}
Configure the PVLAN on the port.
set pvlan
primary vlan secondary vlan mod/port