121
Step Command Remarks
user-name-format mac-address
[ {
with-hyphen
|
without-hyphen
} [
lowercase
|
uppercase
] ]
•
Use one shared user account for
all users:
mac-authentication
user-name-format
fixed
[
account
name
] [
password
{
cipher
|
simple
}
string
]
MAC authentication. The MAC
address is in the hexadecimal
notation without hyphens, and
letters are in lower case.
Configuring MAC authentication timers
MAC authentication uses the following timers:
•
Offline detect timer
—Sets the interval that the device waits for traffic from a user before the
device regards the user idle. When the offline detection feature is enabled, the device logs off
the user and requests to stop accounting for the user after the timer expires.
After you set the offline detect timer, assign the same value to the MAC address aging timer by
using the
mac-address timer
command. This operation prevents a MAC authenticated user
from being offline within the offline detect timer due to MAC address entry expiration.
•
Quiet
timer
—Sets the interval that the device must wait before the device can perform MAC
authentication for a user that has failed MAC authentication. All packets from the MAC address
are dropped during the quiet time. This quiet mechanism prevents repeated authentication from
affecting system performance.
•
Server timeout timer
—Sets the interval that the device waits for a response from a RADIUS
server before the device regards the RADIUS server unavailable. If the timer expires during
MAC authentication, the user cannot access the network.
To configure MAC authentication timers:
Step Command Remarks
1.
Enter system view.
system-view
N/A
2.
Configure MAC
authentication timers.
mac-authentication
timer
{
offline-detect
offline-detect-value
|
quiet
quiet-value
|
server-timeout
server-timeout-value
}
By default, the offline detect
timer is 300 seconds, the quiet
timer is 60 seconds, and the
server timeout timer is 100
seconds.
Setting the maximum number of concurrent MAC
authentication users on a port
Perform this task to prevent the system resources from being overused.
To set the maximum number of concurrent MAC authentication users on a port:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter interface view.
interface interface-type
interface-number
N/A
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...