189
The 802.1X MAC address binding feature automatically binds MAC addresses of authenticated
802.1X users to the users' access port and generates 802.1X MAC address binding entries.
802.1X MAC address binding entries, both automatically generated and manually added, never age
out. They can survive a user logoff or a device reboot. To delete an entry, you must use the
undo
dot1x mac-binding mac-address
command. An 802.1X MAC address binding entry cannot be
deleted when the user in the entry is online.
After the number of 802.1X MAC address binding entries reaches the upper limit of concurrent
802.1X users (set by using the
dot1x max-user
command), the following restrictions exist:
•
Users not in the binding entries will fail authentication even after users in the binding entries go
offline.
•
New 802.1X MAC address binding entries are not allowed.
Examples
# Enable 802.1X MAC address binding on Ten-GigabitEthernet 1/0/1.
<Sysname> system-view
[Sysname] interface ten-gigabitethernet 1/0/1
[Sysname-Ten-GigabitEthernet1/0/1] dot1x mac-binding enable
Related commands
dot1x
dot1x mac-binding
dot1x port-method
dot1x mandatory-domain
Use
dot1x mandatory-domain
to specify a mandatory 802.1X authentication domain on a port.
Use
undo dot1x mandatory-domain
to restore the default.
Syntax
dot1x mandatory-domain
domain-name
undo dot1x
mandatory-domain
Default
No mandatory 802.1X authentication domain is specified on a port.
Views
Layer 2 Ethernet interface view
Layer 2 aggregate interface view
Predefined user roles
network-admin
mdc-admin
Parameters
domain-name
: Specifies the ISP domain name, a case-insensitive string of 1 to 255 characters.
Usage guidelines
When the system authenticates an 802.1X user trying to access a port, it selects an authentication
domain in the following order:
1.
Mandatory domain.
2.
ISP domain specified in the username.
Содержание FlexNetwork 7500 Series
Страница 350: ...335 Related commands display port security port security enable ...
Страница 379: ...364 Sysname system view Sysname keychain abc mode absolute Sysname keychain abc tcp kind 252 ...
Страница 519: ...504 Related commands display ssh2 algorithm ssh2 algorithm cipher ssh2 algorithm key exchange ssh2 algorithm mac ...