215
For more information about user profiles, see
BRAS Services Configuration Guide
.
Periodic MAC reauthentication
Periodic MAC reauthentication tracks the connection status of online users, and updates the
authorization attributes assigned by the RADIUS server. The attributes include the ACL and VLAN.
The device reauthenticates an online MAC authentication user periodically only after it receives the
termination action
Radius-request
from the authentication server for this user. The Session-Timeout
attribute (session timeout period) assigned by the server is the reauthentication interval. To display
the server-assigned Session-Timeout and Termination-Action attributes, use the
display
mac-authentication connection
command. Support for the server configuration and assignment of
Session-Timeout and Termination-Action attributes depends on the server model.
Restrictions and guidelines: MAC authentication
configuration
When you configure MAC authentication, follow these restrictions and guidelines:
•
MAC authentication is exclusive with link aggregation group or service loopback group.
{
You cannot enable MAC authentication on a port already in a link aggregation group or a
service loopback group.
{
You cannot add a MAC authentication-enabled port to a link aggregation group or a service
loopback group.
•
If the MAC address that has failed authentication is a static MAC address or a MAC address
that has passed any security authentication, the device does not mark the MAC address as a
silent address.
MAC authentication tasks at a glance
Tasks at a glance
(Required.)
(Optional.)
Specifying a MAC authentication domain
(Optional.)
Configuring the user account format
(Optional.)
Configuring MAC authentication timers
(Optional.)
Enabling MAC authentication offline detection
(Optional.)
Setting the maximum number of concurrent MAC authentication users on a port
(Optional.)
Enabling MAC authentication multi-VLAN mode on a port
(Optional.)
Configuring MAC authentication delay
(Optional.)
Configuring a MAC authentication guest VLAN
(Optional.)
Configuring a MAC authentication critical VLAN
(Optional.)
Configuring the keep-online feature
(Optional.)
Including user IP addresses in MAC authentication requests