
82
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter interface view.
interface
interface-type
interface-number
N/A
3.
Set the maximum number of
concurrent MAC authentication
users on the port
mac-authentication max-user
user-number
By default, the maximum number
of concurrent MAC
authentication users is 256.
Displaying and maintaining MAC authentication
Execute
display
commands in any view and
reset
commands in user view.
Task Command
Display MAC authentication information.
display mac-authentication
[
interface
interface-type
interface-number
]
Clear MAC authentication statistics.
reset mac-authentication statistics
[
interface
interface-type
interface-number
]
MAC authentication configuration examples
Local MAC authentication configuration example
Network requirements
As shown in
, configure local MAC authentication on port Ten-GigabitEthernet 1/0/1 to
control Internet access, as follows:
•
Configure the device to detect whether a user has gone offline every 180 seconds, and if a user fails
authentication, deny the user for 180 seconds.
•
Configure all users to belong to the ISP domain
aabbcc
, and specify local authentication for users
in the domain.
•
Use the MAC address of each user as the username and password for authentication, and require
the MAC addresses be hyphenated and in lower case.
Figure 32
Network diagram
Configuration procedure
# Add a network access local user, configure both the username and password as the host's MAC
address 00-e0-fc-12-34-56, and specify the LAN access service for the account.
<Device> system-view