108
•
Authentication
—Security modes in this category implement MAC authentication, 802.1X
authentication, or a combination of these two authentication methods.
describes the port security modes and the security features.
Table 9
Port security modes
Purpose Security
mode
Features that can
be triggered
Turning off the port security
feature
noRestrictions (the default mode)
In this mode, port security is disabled on the port,
and access to the port is not restricted.
—
Controlling MAC address
learning
autoLearn
NTK/intrusion
protection
secure
Performing 802.1X
authentication
userLogin —
userLoginSecure
NTK/intrusion
protection
userLoginSecureExt
userLoginWithOUI
macAddressWithRadius
NTK/intrusion
protection
Performing a combination of
MAC authentication and
Or
macAddressOrUserLoginSecure
NTK/intrusion
protection
macAddressOrUserLoginSecureExt
Else
macAddressElseUserLoginSecure
macAddressElseUserLoginSecureExt
•
userLogin
—Specifies 802.1X authentication and port-based access control.
•
macAddress
—Specifies MAC authentication.
•
Else
—Specifies that the authentication method before
Else
is applied first. If the authentication fails,
whether to turn to the authentication method following
Else
depends on the protocol type of the
authentication request.
•
Or
—Typically, in a security mode with
Or
, the authentication method to be used depends on the
protocol type of the authentication request.
•
userLogin
with
Secure
—Specifies 802.1X authentication and MAC-based access control.
•
Ext
—Indicates allowing multiple 802.1X users to be authenticated and serviced at the same time. A
security mode without
Ext
allows only one user to pass 802.1X authentication.
Controlling MAC address learning
autoLearn
A port in this mode can learn MAC addresses and allow frames from learned or configured MAC
addresses to pass. The automatically learned MAC addresses are secure MAC addresses. You can also
configure secure MAC addresses by using the
port-security mac-address security
command. A secure
MAC address never ages out by default.
When the number of secure MAC addresses reaches the upper limit, the port transitions to secure mode.
Содержание A5830 Series
Страница 207: ...199 Figure 62 SFTP client interface ...