1-1
1
MAC Authentication Configuration
When configuring MAC authentication, go to these sections for information you are interested in:
z
MAC Authentication Overview
z
Related Concepts
z
Configuring MAC Authentication
z
Displaying and Maintaining MAC Authentication
z
MAC Authentication Configuration Examples
MAC Authentication Overview
MAC authentication provides a way for authenticating users based on ports and MAC addresses. Once
detecting a new MAC address, the device initiates the authentication process. MAC authentication
requires neither client software to be installed on the hosts, nor any username or password to be
entered by users during authentication.
Currently, the device supports two MAC authentication modes: Remote Authentication Dial-In User
Service (RADIUS) based MAC authentication and local MAC authentication. For detailed information
about RADIUS authentication and local authentication, refer to
AAA Configuration
of the
Security
Volume
.
MAC authentication supports two types of usernames:
z
MAC address, where the MAC address of a user serves as both the username and password.
z
Fixed username, where all users use the same preconfigured username and password for
authentication, regardless of the MAC addresses.
RADIUS-Based MAC Authentication
In RADIUS-based MAC authentication, the device serves as a RADIUS client and requires a RADIUS
server to cooperate with it.
z
If the type of username is MAC address, the device forwards a detected MAC address as the
username and password to the RADIUS server for authentication of the user.
z
If the type of username is fixed username, the device sends the same username and password
configured locally to the RADIUS server for authentication of each user.
If the authentication succeeds, the user will be granted permission to access the network resources.
Local MAC Authentication
In local MAC authentication, the device performs authentication of users locally and different items
need to be manually configured for users on the device according to the specified type of username:
z
If the type of username is MAC address, a local user must be configured for each user on the
device, using the MAC address of the accessing user as both the username and password.
z
If the type of username is fixed username, a single username and optionally a single password are
required for the device to authenticate all users.
Содержание 4500G PWR 24-Port
Страница 200: ...1 5 ProviderB GigabitEthernet1 0 2 undo stp enable ProviderB GigabitEthernet1 0 2 bpdu tunnel dot1q stp ...
Страница 252: ...1 7 Clearing ARP entries from the ARP table may cause communication failures ...
Страница 362: ...i Table of Contents 1 Dual Stack Configuration 1 1 Dual Stack Overview 1 1 Configuring Dual Stack 1 1 ...
Страница 407: ...1 8 1 1 ms 1 ms 1 ms 1 1 6 1 2 1 ms 1 ms 1 ms 1 1 4 1 3 1 ms 1 ms 1 ms 1 1 2 2 Trace complete ...
Страница 786: ...1 16 3 In the case of PIM SM use the display current configuration command to check the BSR and RP information ...
Страница 1387: ...1 23 ...
Страница 1443: ...i Table of Contents 1 URPF Configuration 1 1 URPF Overview 1 1 What is URPF 1 1 How URPF Works 1 1 Configuring URPF 1 2 ...
Страница 1720: ...ii Single Device Upgrade 3 4 IRF System Upgrade 3 5 ...