115
•
Do not configure this feature together with the MAC authentication guest VLAN on a port. If both
features are configured, users in the MAC authentication guest VLAN cannot perform a new
round of authentication.
To include user IP addresses in MAC authentication requests:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter Layer 2 Ethernet
interface view.
interface
interface-type
interface-number
N/A
3.
Include user IP addresses in
MAC authentication requests.
mac-authentication carry
user-ip
By default, a MAC
authentication request does not
include the user IP address.
Displaying and maintaining MAC authentication
Execute
display
commands in any view and
reset
commands in user view.
Task Command
Display MAC authentication information.
display mac-authentication
[
interface
interface-type
interface-number
]
Display MAC authentication connections.
display mac-authentication connection
[
interface
interface-type interface-number
|
slot
slot-number
|
user-mac
mac-addr
|
user-name
user-name
]
Clear MAC authentication statistics.
reset mac-authentication statistics
[
interface
interface-type interface-number
]
Remove users from the MAC authentication
critical VLAN on a port.
reset mac-authentication critical-vlan interface
interface-type interface-number
[
mac-address
mac-address
]
Remove users from the MAC authentication
critical voice VLAN on a port.
reset mac-authentication critical-voice-vlan
interface
interface-type interface-number
[
mac-address
mac-address
]
Remove users from the MAC authentication
guest VLAN on a port.
reset mac-authentication guest-vlan interface
interface-type interface-number
[
mac-address
mac-address
]
MAC authentication configuration examples
Local MAC authentication configuration example
Network requirements
As shown in
, the device performs local MAC authentication on FortyGigE 1/1/1 to control
Internet access of users.
Configure the device to meet the following requirements:
•
Detect whether a user has gone offline every 180 seconds.
•
Deny a user for 180 seconds if the user fails MAC authentication.
•
Authenticate all users in ISP domain
bbb
.