213
A port in this mode can learn MAC addresses. The automatically learned MAC addresses are
not added to the MAC address table as dynamic MAC address. Instead, these MAC addresses
are added to the secure MAC address table as secure MAC addresses. You can also configure
secure MAC addresses by using the
port-security mac-address security
command.
A port in autoLearn mode allows frames sourced from the following MAC addresses to pass:
{
Secure MAC addresses.
{
MAC addresses configured by using the
mac-address dynamic
and
mac-address static
commands.
When the number of secure MAC addresses reaches the upper limit, the port transitions to
secure mode.
•
secure.
MAC address learning is disabled on a port in secure mode. You configure MAC addresses by
using the
mac-address static
and
mac-address dynamic
commands. For more information
about configuring MAC address table entries, see
Layer 2—LAN Switching Configuration
Guide
.
A port in secure mode allows only frames sourced from the following MAC addresses to pass:
{
Secure MAC addresses.
{
MAC addresses configured by using the
mac-address dynamic
and
mac-address static
commands.
Performing 802.1X authentication
•
userLogin.
A port in this mode performs 802.1X authentication and implements port-based access control.
The port can service multiple 802.1X users. Once an 802.1X user passes authentication on the
port, any subsequent 802.1X users can access the network through the port without
authentication.
•
userLoginSecure.
A port in this mode performs 802.1X authentication and implements MAC-based access control.
The port services only one user passing 802.1X authentication.
•
userLoginSecureExt.
This mode is similar to the userLoginSecure mode except that this mode supports multiple
online 802.1X users.
•
userLoginWithOUI.
This mode is similar to the userLoginSecure mode. The difference is that a port in this mode
also permits frames from one user whose MAC address contains a specific OUI.
In this mode, the port performs OUI check at first. If the OUI check fails, the port performs
802.1X authentication. The port permits frames that pass OUI check or 802.1X authentication.
NOTE:
An OUI is a 24-bit number that uniquely identifies a vendor, manufacturer, or organization. In
MAC addresses, the first three octets are the OUI.
Performing MAC authentication
macAddressWithRadius: A port in this mode performs MAC authentication, and services multiple
users.
Performing a combination of MAC authentication and 802.1X authentication
•
macAddressOrUserLoginSecure.
This mode is the combination of the macAddressWithRadius and userLoginSecure modes. The
mode allows one 802.1X authentication user and multiple MAC authentication users to log in.
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...