216
Step Command
Remarks
that port security allows on a port.
If you use the
vlan
keyword
without the
vlan-id-list
argument,
this command sets the maximum
number of secure MAC addresses
for each VLAN on the port.
If you use the
vlan
keyword with
the
vlan-id-list
argument, this
command sets the maximum
number of secure MAC addresses
for the specified VLANs on the
port.
Setting the port security mode
Before you set a port security mode for a port, complete the following tasks:
•
Disable 802.1X and MAC authentication.
•
Verify that the port does not belong to an aggregation group or service loopback group.
•
If you are configuring the autoLearn mode, set port security's limit on the number of secure
MAC addresses. You cannot change the setting when the port is operating in autoLearn mode.
When you set the port security mode, follow these guidelines:
•
You can specify a port security mode when port security is disabled, but your configuration
cannot take effect.
•
Changing the port security mode of a port logs off the online users of the port.
•
Do not enable 802.1X authentication or MAC authentication on a port where port security is
configured.
•
The device supports the URL attribute assigned by a RADIUS server in the following port
security modes:
{
mac-authentication
.
{
mac-else-userlogin-secure.
{
mac-else-userlogin-secure-ext
.
{
userlogin-secure.
{
userlogin-secure-ext
.
{
userlogin-secure-or-mac.
{
userlogin-secure-or-mac-ext
.
{
userlogin-withoui
.
During authentication, a user is redirected to the Web interface specified by the
server-assigned URL attribute. After the user passes the Web authentication, the RADIUS
server records the MAC address of the Web user and uses a DM (Disconnect Message) to log
off the Web user. When the user initiates 802.1X or MAC authentication again, it will pass the
authentication and come online successfully.
To set the port security mode:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
(Optional.) Set an OUI value
for user authentication.
port-security oui index
index-value
mac-address
By default, no OUI values are
configured for user authentication.
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...