80
•
The device fails to authorize the specified ACL or user profile to the user.
•
The server assigns a nonexistent ACL or user profile to the user.
If this feature is disabled, the device does not log off users who fail ACL or user profile authorization.
Aging timer for secure MAC addresses
When secure MAC addresses are aged out, they are removed from the secure MAC address table.
The aging timer applies to all configured sticky secure MAC addresses and those automatically
learned by a port. To disable the aging timer, set the timer to 0.
Silence period
This period sets the duration during which a port remains disabled when the port receives illegal
frames. The intrusion protection action on the port must be
Disable port temporarily
.
Authentication OUI
The configured OUI value takes effect only when the port authentication mode is
userLoginWithOUI
.
In userLoginWithOUI mode, the port allows a maximum of two users to pass through, including:
•
One user who passes 802.1X authentication.
•
One user whose MAC address matches any one of the OUIs configured on the device.
Port security settings
Port security modes
Port security supports the following categories of security modes:
•
MAC learning control
—Includes two modes: autoLearn and secure. MAC address learning is
permitted on a port in autoLearn mode and disabled in secure mode.
•
Authentication
—Security modes in this category implement MAC authentication, 802.1X
authentication, or a combination of these two authentication methods.
Upon receiving a frame, the port in a security mode searches the MAC address table for the source
MAC address. If a match is found, the port forwards the frame. If no match is found, the port learns
the MAC address or performs authentication, depending on the security mode. If the frame is illegal,
the port takes the predefined NTK or intrusion protection action. Outgoing frames are not restricted
by port security's NTK action unless they trigger the NTK feature.
describes the port security modes and the security features.
Table 19 Port security modes
Purpose Security
mode
Features that can
be triggered
Turning off the port security
feature
noRestrictions (the default mode)
In this mode, port security is disabled on the port
and access to the port is not restricted.
N/A
autoLearn
NTK/intrusion
protection
secure
Perform 802.1X authentication:
userLogin N/A
userLoginSecure
NTK/intrusion
protection
userLoginSecureExt
userLoginWithOUI