
197
•
You can specify a port security mode when port security is disabled, but your configuration
cannot take effect.
•
Changing the port security mode of a port logs off the online users of the port.
•
Do not enable 802.1X authentication or MAC authentication on a port where port security is
configured.
•
The device supports the URL attribute assigned by a RADIUS server in the following port
security modes:
{
mac-authentication
.
{
mac-else-userlogin-secure.
{
mac-else-userlogin-secure-ext
.
{
userlogin-secure.
{
userlogin-secure-ext
.
{
userlogin-secure-or-mac.
{
userlogin-secure-or-mac-ext
.
{
userlogin-withoui
.
During authentication, a user is redirected to the Web interface specified by the
server-assigned URL attribute. After the user passes the Web authentication, the RADIUS
server records the MAC address of the Web user and uses a DM (Disconnect Message) to log
off the Web user. When the user initiates 802.1X or MAC authentication again, it will pass the
authentication and come online successfully.
To enable a port security mode:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
(Optional.) Set an OUI value
for user authentication.
port-security oui index
index-value
mac-address
oui-value
By default, no OUI value is
configured for user
authentication.
This command is required for the
userlogin-withoui
mode.
You can set multiple OUIs, but
when the port security mode is
userlogin-withoui
, the port
allows one 802.1X user and only
one user that matches one of the
specified OUIs.
3.
Enter Layer 2 Ethernet
interface view.
interface
interface-type
interface-number
N/A
4.
Set the port security mode.
port-security
port-mode
{
autolearn
|
mac-authentication
|
mac-else-userlogin-secure
|
mac-else-userlogin-secure-ext
|
secure
|
userlogin
|
userlogin-secure
|
userlogin-secure-ext
|
userlogin-secure-or-mac
|
userlogin-secure-or-mac-ext
|
userlogin-withoui
}
By default, a port operates in
noRestrictions mode.
After enabling port security, you
can change the port security
mode of a port only when the port
is operating in noRestrictions (the
default) mode. To change the port
security mode for a port in any
other mode, first use the
undo
port-security port-mode
command to restore the default
port security mode.
Содержание 10500 series
Страница 326: ...312 No duration limit for this SA ...