C
HAPTER
14
| Security Measures
Network Access (MAC Address Authentication)
– 278 –
◆
Authenticated MAC addresses are stored as dynamic entries in the
switch secure MAC address table and are removed when the aging time
expires. The maximum number of secure MAC addresses supported for
the switch system is 1024.
◆
Configured static MAC addresses are added to the secure address table
when seen on a switch port. Static addresses are treated as
authenticated without sending a request to a RADIUS server.
◆
When port status changes to down, all MAC addresses mapped to that
port are cleared from the secure MAC address table. Static VLAN
assignments are not restored.
◆
The RADIUS server may optionally return a VLAN identifier list to be
applied to the switch port. The following attributes need to be
configured on the RADIUS server.
■
Tunnel-Type
= VLAN
■
Tunnel-Medium-Type
= 802
■
Tunnel-Private-Group-ID
= 1u,2t [
VLAN ID list
]
The VLAN identifier list is carried in the RADIUS “Tunnel-Private-Group-
ID” attribute. The VLAN list can contain multiple VLAN identifiers in the
format “1u,2t,3u” where “u” indicates an untagged VLAN and “t” a
tagged VLAN.
◆
The RADIUS server may optionally return dynamic QoS assignments to
be applied to a switch port for an authenticated user. The “Filter-ID”
attribute (attribute 11) can be configured on the RADIUS server to pass
the following QoS information:
◆
Multiple profiles can be specified in the Filter-ID attribute by using a
semicolon to separate each profile.
For example, the attribute “service-policy-in=pp1;rate-limit-
input=100” specifies that the diffserv profile name is “pp1,” and the
ingress rate limit profile value is 100 kbps.
◆
If duplicate profiles are passed in the Filter-ID attribute, then only the
first profile is used.
For example, if the attribute is “service-policy-in=p1;service-policy-
in=p2”, then the switch applies only the DiffServ profile “p1.”
Table 17: Dynamic QoS Profiles
Profile
Attribute Syntax
Example
DiffServ
service-policy-in
=
policy-map-name
service-policy-in=p1
Rate Limit
rate-limit-input
=
rate
rate-limit-input=100
(in units of Kbps)
802.1p
switchport-priority-default
=
value
switchport-priority-default=2
Содержание ES3510MA
Страница 1: ...Management Guide www edge core com 8 Port Layer 2 Fast Ethernet Switch...
Страница 4: ...ABOUT THIS GUIDE 4...
Страница 30: ...CONTENTS 30...
Страница 40: ...FIGURES 40...
Страница 46: ...TABLES 46...
Страница 48: ...SECTION I Getting Started 48...
Страница 72: ...SECTION II Web Configuration 72...
Страница 88: ...CHAPTER 3 Using the Web Interface Navigating the Web Browser Interface 88...
Страница 115: ...CHAPTER 4 Basic Management Tasks Resetting the System 115 Figure 23 Restarting the Switch Regularly...
Страница 116: ...CHAPTER 4 Basic Management Tasks Resetting the System 116...
Страница 154: ...CHAPTER 5 Interface Configuration VLAN Trunking 154...
Страница 216: ...CHAPTER 8 Spanning Tree Algorithm Configuring Interface Settings for MSTP 216...
Страница 350: ...CHAPTER 14 Security Measures DHCP Snooping 350...
Страница 440: ...CHAPTER 17 IP Services Displaying the DNS Cache 440...
Страница 484: ...CHAPTER 19 Using the Command Line Interface CLI Command Groups 484...
Страница 554: ...CHAPTER 21 System Management Commands Switch Clustering 554...
Страница 574: ...CHAPTER 22 SNMP Commands 574...
Страница 582: ...CHAPTER 23 Remote Monitoring Commands 582...
Страница 636: ...CHAPTER 24 Authentication Commands Management IP Filter 636...
Страница 736: ...CHAPTER 29 Port Mirroring Commands RSPAN Mirroring Commands 736...
Страница 816: ...CHAPTER 34 VLAN Commands Configuring Voice VLANs 816...
Страница 830: ...CHAPTER 35 Class of Service Commands Priority Commands Layer 3 and 4 830...
Страница 848: ...CHAPTER 36 Quality of Service Commands 848...
Страница 900: ...CHAPTER 38 LLDP Commands 900...
Страница 910: ...CHAPTER 39 Domain Name Service Commands 910...
Страница 916: ...CHAPTER 40 DHCP Commands DHCP Client 916...
Страница 948: ...CHAPTER 41 IP Interface Commands IPv6 Interface 948...
Страница 950: ...SECTION IV Appendices 950...
Страница 982: ...INDEX 982...
Страница 983: ......
Страница 984: ...ES3510MA E032010 ST R01 149100000046A...