189
Port security parameters:
Port security : Enabled
AutoLearn aging time : 0 min
Disableport timeout : 20 s
MAC move : Denied
Authorization fail : Online
NAS-ID profile is not configured
OUI value list :
Index : 1 Value : 123401
Index : 2 Value : 123402
Index : 3, Value : 123403
Index : 4, Value : 123404
Index : 5, Value : 123405
Ten-GigabitEthernet1/0/1 is link-up
Port mode : userLoginWithOUI
NeedToKnow mode : Disabled
Intrusion protection mode : NoAction
Security MAC address attribute
Learning mode : Sticky
Aging type : Periodical
Max secure MAC addresses : Not configured
Current secure MAC addresses : 1
Authorization : Permitted
NAS-ID profile is not configured
# Display information about the online 802.1X user to verify 802.1X configuration.
[Device] display dot1x
# Verify that the port also allows one user whose MAC address has an OUI among the specified OUIs
to pass authentication.
[Device] display mac-address interface ten-gigabitethernet 1/0/1
MAC Address VLAN ID State Port Aging
1234-0300-0011 1 Learned Ten-GigabitEthernet1/0/1 Y
macAddressElseUserLoginSecure configuration example
Network requirements
As shown in
, a client is connected to the device through Ten-GigabitEthernet 1/0/1. The device
authenticates the client by a RADIUS server. If the authentication succeeds, the client is authorized to
access the Internet.
Configure port Ten-GigabitEthernet 1/0/1
of the device to meet the following requirements:
•
Allow more than one MAC authenticated user to log on.
•
For 802.1X users, perform MAC authentication first and then, if MAC authentication fails, 802.1X
authentication. Allow only one 802.1X user to log on.
•
Use the MAC address of each user as the username and password for authentication. A MAC
address is in the hexadecimal notation with hyphens, and letters are in upper case.
•
Set the total number of MAC authenticated users and 802.1X authenticated users to 64.