120
MAC authentication is exclusive with link aggregation group or service loopback group.
•
You cannot enable MAC authentication on a port already in a link aggregation group or a
service loopback group.
•
You cannot add a MAC authentication-enabled port to a link aggregation group or a service
loopback group.
To enable MAC authentication:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enable MAC authentication
globally.
mac-authentication
By default, MAC authentication
is disabled globally.
3.
Enter interface view.
interface interface-type
interface-number
N/A
4.
Enable MAC authentication on
the port.
mac-authentication
By default, MAC authentication
is disabled on a port.
Specifying a MAC authentication domain
By default, MAC authentication users are in the system default authentication domain. To implement
different access policies for users, you can use one of the following methods to specify
authentication domains for MAC authentication users:
•
Specify a global authentication domain in system view. This domain setting applies to all ports
enabled with MAC authentication.
•
Specify an authentication domain for an individual port in interface view.
MAC authentication chooses an authentication domain for users on a port in this order: the
port-specific domain, the global domain, and the default domain. For more information about
authentication domains, see "
."
To specify an authentication domain for MAC authentication users:
Step Command Remarks
1.
Enter system view.
system-view
N/A
2.
Specify an authentication
domain for MAC
authentication users.
•
In system view:
mac-authentication domain
domain-name
•
In interface view:
a. interface
interface-type
interface-number
b. mac-authentication
domain
domain-name
By default, the system default
authentication domain is used for
MAC authentication users.
Configuring the user account format
Step Command Remarks
1.
Enter system view.
system-view
N/A
2.
Configure the MAC
authentication user
account format.
•
Use one MAC-based user
account for each user:
mac-authentication
By default, the device uses the
MAC address of a user as the
username and password for
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...