126
The device uses LLDP to identify voice users. For information about LLDP, see
Layer 2—LAN
Switching Configuration Guide
.
•
Enable voice VLAN on the port.
For information about voice VLANs, see
Layer 2—LAN Switching Configuration Guide
.
Configuration procedure
To enable the MAC authentication critical voice VLAN feature on a port:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter Ethernet interface
view.
interface interface-type
interface-number
N/A
3.
Enable the MAC
authentication critical voice
VLAN feature on a port.
mac-authentication
critical-voice-vlan
By default, the MAC
authentication critical voice VLAN
feature is disabled on a port.
Configuring periodic MAC reauthentication
Overview
Periodic MAC reauthentication reauthenticates online MAC authentication users at a
user-configurable reauthentication interval. The reauthentication feature tracks the connection
status of online users and updates the authorization attributes assigned by the server. The attributes
include the ACL and VLAN.
By default, the device logs off online MAC authentication users if no server is reachable for MAC
reauthentication. The keep-online feature keeps authenticated MAC authentication users online
when no server is reachable for MAC reauthentication.
Configuration restrictions and guidelines
When you configure periodic MAC reauthentication, follow these restrictions and guidelines:
•
The server-assigned RADIUS Session-Timeout (attribute 27) and Termination-Action (attribute
29) attributes together can affect the periodic MAC reauthentication feature. To display the
server-assigned Session-Timeout and Termination-Action attributes, use the
display
mac-authentication connection
command (see
Security Command Reference
).
{
If the termination action is logging off users, periodic MAC reauthentication takes effect only
when the periodic reauthentication timer is shorter than the session timeout timer. If the
session timeout timer is shorter, the device logs off online authenticated users when the
session timeout timer expires.
{
If the termination action is reauthenticating users, the periodic MAC reauthentication
configuration on the device cannot take effect. The device reauthenticates online MAC
authentication users after the server-assigned session timeout timer expires.
Support for the server configuration and assignment of session timeout timer and termination
action depends on the server model.
•
You can set the periodic reauthentication timer either in system view or in interface view by
using the
mac-authentication timer reauth-period
command. A change to the periodic
reauthentication timer applies to online users only after the old timer expires.
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...