
BigIron RX Series Configuration Guide
927
53-1002253-01
Configuring multi-device port authentication
31
Support for authenticating multiple MAC addresses
on an interface
The multi-device port authentication feature allows multiple MAC addresses to be authenticated or
denied authentication on each interface. The maximum number of MAC addresses that can be
authenticated on each interface is 256. The default is 32.
Support for multi-device port authentication and 802.1x
on the same interface
On the BigIron RX, multi-device port authentication and 802.1x security can be enabled on the
same port. However, only one of them can authenticate a MAC address/802.1x client. If an 802.1x
client responds, the software assumes that the MAC should be authenticated using 802.1x
protocol mechanisms and multi-device port authentication for that MAC is aborted. Also, at any
given time, a port can have either 802.1x clients or multi-device port authentication clients but not
both.
Configuring multi-device port authentication
Configuring multi-device port authentication on the BigIron RX consists of the following tasks:
•
Enabling multi-device port authentication globally and on individual interfaces
•
Configuring an Authentication Method List for 802.1x
•
Setting RADIUS Parameters
•
Specifying the format of the MAC addresses sent to the RADIUS server (optional)
•
Specifying the authentication-failure action (optional)
•
Defining MAC address filters (optional)
•
Configuring dynamic VLAN assignment (optional)
•
Specifying to which VLAN a port is moved after its RADIUS-specified VLAN assignment expires
(optional)
•
Saving dynamic VLAN assignments to the running configuration file (optional)
•
Clearing authenticated MAC addresses (optional)
•
Disabling aging for authenticated MAC addresses (optional)
•
Specifying the aging time for blocked MAC addresses (optional)
Enabling multi-device port authentication
You globally enable multi-device port authentication on the device.
To globally enable multi-device port authentication on the device, enter the following command.
BigIron RX(config)# mac-authentication enable
Syntax: [no] mac-authentication enable
Syntax: [no] mac-authentication enable
<slot>/<portnum>
| all
The all option enables the feature on all interfaces at once.
Содержание BigIron RX Series
Страница 100: ...24 BigIron RX Series Configuration Guide 53 1002253 01 Logging on through the Web Management Interface 2 ...
Страница 192: ...116 BigIron RX Series Configuration Guide 53 1002253 01 Configuring authentication method lists 4 ...
Страница 228: ...152 BigIron RX Series Configuration Guide 53 1002253 01 Enabling WAN PHY mode support 6 ...
Страница 312: ...236 BigIron RX Series Configuration Guide 53 1002253 01 Displaying IP information 7 ...
Страница 356: ...280 BigIron RX Series Configuration Guide 53 1002253 01 Resetting LLDP statistics 9 ...
Страница 402: ...326 BigIron RX Series Configuration Guide 53 1002253 01 Transparent firewall mode 11 ...
Страница 432: ...356 BigIron RX Series Configuration Guide 53 1002253 01 SuperSpan 12 ...
Страница 500: ...424 BigIron RX Series Configuration Guide 53 1002253 01 MRP CLI example 14 ...
Страница 580: ...504 BigIron RX Series Configuration Guide 53 1002253 01 Configuring multicast traffic engineering 18 ...
Страница 591: ...BigIron RX Series Configuration Guide 515 53 1002253 01 Displaying traffic reduction 19 ...
Страница 592: ...516 BigIron RX Series Configuration Guide 53 1002253 01 Displaying traffic reduction 19 ...
Страница 598: ...522 BigIron RX Series Configuration Guide 53 1002253 01 Viewing Layer 2 ACLs 20 ...
Страница 656: ...580 BigIron RX Series Configuration Guide 53 1002253 01 Trunk formation 22 ...
Страница 754: ...678 BigIron RX Series Configuration Guide 53 1002253 01 Displaying RIP filters 24 ...
Страница 814: ...738 BigIron RX Series Configuration Guide 53 1002253 01 Displaying OSPF information 25 ...
Страница 932: ...856 BigIron RX Series Configuration Guide 53 1002253 01 Generalized TTL security mechanism support 26 ...
Страница 980: ...904 BigIron RX Series Configuration Guide 53 1002253 01 Clearing IS IS information 28 ...
Страница 1000: ...924 BigIron RX Series Configuration Guide 53 1002253 01 Using secure copy 30 ...
Страница 1088: ...1012 BigIron RX Series Configuration Guide 53 1002253 01 IP source guard 35 ...
Страница 1108: ...1032 BigIron RX Series Configuration Guide 53 1002253 01 Reading CDP packets 37 ...
Страница 1126: ...1050 BigIron RX Series Configuration Guide 53 1002253 01 Clearing sFlow statistics 39 ...
Страница 1140: ...1064 BigIron RX Series Configuration Guide 53 1002253 01 802 1s Multiple Spanning Tree Protocol 40 ...
Страница 1324: ...1248 BigIron RX Series Configuration Guide 53 1002253 01 Displaying OSPFv3 information 48 ...
Страница 1363: ...BigIron RX Series Configuration Guide 1287 53 1002253 01 Continuous System Monitor 51 ...
Страница 1364: ...1288 BigIron RX Series Configuration Guide 53 1002253 01 Continuous System Monitor 51 ...
Страница 1404: ...1328 BigIron RX Series Configuration Guide 53 1002253 01 Commands That Require a Reload D ...
Страница 1458: ...1382 BigIron RX Series Configuration Guide 53 1002253 01 VSRP E ...