Operation Manual – MAC Address Authentication
H3C S3100 Series Ethernet Switches
Chapter 1 MAC Authentication Configuration
1-2
z
In fixed mode, all users’ MAC addresses are automatically mapped to the
configured local passwords and usernames.
z
The service type of a local user needs to be configured as lan-access.
1.2 Related Concepts
1.2.1 MAC Authentication Timers
The following timers function in the process of MAC authentication:
z
Offline detect timer: At this interval, the switch checks to see whether an online
user has gone offline. Once detecting that a user becomes offline, the switch
sends a stop-accounting notice to the RADIUS server.
z
Quiet timer: Whenever a user fails MAC authentication, the switch does not initiate
any MAC authentication of the user during a period defined by this timer.
z
Server timeout timer: During authentication of a user, if the switch receives no
response from the RADIUS server in this period, it assumes that its connection to
the RADIUS server has timed out and forbids the user from accessing the
network.
1.2.2 Quiet MAC Address
When a user fails MAC authentication, the MAC address becomes a quiet MAC
address, which means that any packets from the MAC address will be discarded simply
by the switch until the quiet timer expires. This prevents an invalid user from being
authenticated repeatedly in a short time.
Caution:
z
If the quiet MAC is the same as the static MAC configured or an
authentication-passed MAC, then the quiet function is not effective.
z
The S3100 series Ethernet switches support quiet MAC function on ports.