214
In this mode, the port performs 802.1X authentication first. By default, if 802.1X authentication
fails, MAC authentication is performed.
However, the port in this mode processes authentication differently when the following
conditions exist:
{
The port is enabled with parallel processing of MAC authentication and 802.1X
authentication.
{
The port is enabled with the 802.1X unicast trigger.
{
The port receives a packet from an unknown MAC address.
Under such conditions, the port sends a unicast EAP-Request/Identity packet to the MAC
address to initiate 802.1X authentication. After that, the port immediately processes MAC
authentication without waiting for the 802.1X authentication result.
•
macAddressOrUserLoginSecureExt.
This mode is similar to the macAddressOrUserLoginSecure mode, except that this mode
supports multiple 802.1X and MAC authentication users.
•
macAddressElseUserLoginSecure.
This mode is the combination of the macAddressWithRadius and userLoginSecure modes, with
MAC authentication having a higher priority as the
Else
keyword implies. The mode allows one
802.1X authentication user and multiple MAC authentication users to log in.
In this mode, the port performs MAC authentication upon receiving non-802.1X frames. Upon
receiving 802.1X frames, the port performs MAC authentication and then, if the authentication
fails, 802.1X authentication.
•
macAddressElseUserLoginSecureExt.
This mode is similar to the macAddressElseUserLoginSecure mode except that this mode
supports multiple 802.1X and MAC authentication users as the
Ext
keyword implies.
Configuration task list
Tasks at a glance
Remarks
(Required.)
(Optional.)
Setting port security's limit on the number of secure
N/A
(Required.)
Setting the port security mode
(Required.)
Configuring port security features
:
•
•
Configuring intrusion protection
Configure one or more port security
features according to the network
requirements.
(Optional.)
Configuring secure MAC addresses
N/A
(Optional.)
Ignoring authorization information from the server
(Optional.)
N/A
(Optional.)
Enabling the authorization-fail-offline feature
N/A
(Optional.)
Applying a NAS-ID profile to port security
(Optional.)
Enabling SNMP notifications for port security
N/A
Enabling port security
Before you enable port security, disable 802.1X and MAC authentication globally.
Содержание FlexFabric 5940 SERIES
Страница 251: ...238 ...