101
Table 8
Relationships of the MAC authentication guest VLAN with other security features
Feature
Relationship description
Reference
MAC authentication
quiet function
The MAC authentication guest VLAN
function has higher priority. A user can
access any resources in the guest VLAN.
Port intrusion protection
The MAC authentication guest VLAN
function has higher priority than the block
MAC action but lower priority than the shut
down port action of the port intrusion
protection feature.
The chapter ―Port security
configuration‖
802.1X guest VLAN on a
port that performs MAC-
based access control
The MAC authentication guest VLAN has a
lower priority.
The chapter ―802.1X
configuration‖
Displaying and maintaining MAC authentication
To do…
Use the command…
Remarks
Display the MAC authentication
related information
display mac-authentication
[
interface
interface-list
] [
|
{
begin
|
exclude
|
include
}
regular-
expression
]
Available in any view
Clear the MAC authentication
statistics
reset mac-authentication statistics
[
interface
interface-list
]
Available in user view
MAC authentication configuration examples
Local MAC authentication configuration example
Network requirements
, perform local MAC authentication on port GigabitEthernet 1/0/1 to control
Internet access. Ensure that:
All users belong to domain aabbcc.net.
Local users use their MAC address as the username and password for MAC authentication. The
MAC addresses are hyphen separated and in lower case.
The access device detects whether a user has gone offline every 180 seconds. When a user fails
authentication, the device does not authenticate the user within 180 seconds.
Figure 37
Network diagram for local MAC authentication
IP network
GE1/0/1
Device
Supplicant
Authenticator
Host
MAC: 00e0-fc12-3456