
92
[Device] mac-authentication domain aabbcc.net
Set the MAC authentication timers.
[Device] mac-authentication timer offline-detect 180
[Device] mac-authentication timer quiet 180
Specify the MAC authentication username format as MAC address, that is, using the MAC address
(with hyphens) of a user as the username and password for MAC authentication of the user.
[Device] mac-authentication user-name-format mac-address with-hyphen
2.
Verify the configuration
Display global MAC authentication information.
<Device> display mac-authentication
MAC address authentication is enabled.
User name format is MAC address, like xx-xx-xx-xx-xx-xx
Fixed username:mac
Fixed password:not configured
Offline detect period is 180s
Quiet period is 180s.
Server response timeout value is 100s
The max allowed user number is 1024 per slot
Current user number amounts to 1
Current domain is aabbcc.net
Silent Mac User info:
MAC ADDR From Port Port Index
Gigabitethernet3/0/1 is link-up
MAC address authentication is enabled
Authenticate success: 1, failed: 0
Current online user number is 1
MAC ADDR Authenticate state AuthIndex
00e0-fc12-3456 MAC_AUTHENTICATOR_SUCCESS 29
<Device> display connection
Index=29 ,[email protected]
MAC=00e0-fc12-3456 ,IP=N/A
Total 1 connection(s) matched.
RADIUS-based MAC authentication configuration
Network requirements
A host is connected to the device through port GigabitEthernet 3/0/1. The device authenticates,
authorizes and keeps accounting on the host through the RADIUS server. See Figure 28.
•
MAC authentication is required on every port to control user access to the Internet.
•
Set the offline detect timer to 180 seconds and the quiet timer to 3 minutes.
•
All users belong to ISP domain 2000.