81
Purpose Security
mode
Features that can
be triggered
macAddressWithRadius
NTK/intrusion
protection
Perform a combination of MAC
authentication and 802.1X
authentication:
Or
macAddressOrUserLoginSecure
NTK/intrusion
protection
macAddressOrUserLoginSecureExt
Else
macAddressElseUserLoginSecure
macAddressElseUserLoginSecureE
xt
•
Control MAC address learning:
{
autoLearn.
A port in this mode can learn MAC addresses. The automatically learned MAC addresses
are not added to the MAC address table as dynamic MAC address. Instead, these MAC
addresses are added to the secure MAC address table as secure MAC addresses. You can
also manually add secure MAC addresses.
A port in autoLearn mode allows frames sourced from the following MAC addresses to
pass:
−
Secure
MAC
addresses.
−
Manually
configured
static and dynamic MAC addresses.
When the number of secure MAC addresses reaches the upper limit, the port transitions to
secure mode.
{
secure.
MAC address learning is disabled on a port in secure mode. A port in secure mode allows
only frames sourced from the following MAC addresses to pass:
−
Secure
MAC
addresses.
−
Manually
configured
static and dynamic MAC addresses.
•
Perform 802.1X authentication:
{
userLogin.
A port in this mode performs 802.1X authentication and implements port-based access
control. The port can service multiple 802.1X users. Once an 802.1X user passes
authentication on the port, any subsequent 802.1X users can access the network through
the port without authentication.
{
userLoginSecure.
A port in this mode performs 802.1X authentication and implements MAC-based access
control. The port services only one user passing 802.1X authentication.
{
userLoginSecureExt.
This mode is similar to the userLoginSecure mode except that this mode supports multiple
online 802.1X users.
{
userLoginWithOUI.
This mode is similar to the userLoginSecure mode. The difference is that a port in this mode
also permits frames from one user whose MAC address contains a specific OUI.
In this mode, the port performs OUI check at first. If the OUI check fails, the port performs
802.1X authentication. The port permits frames that pass OUI check or 802.1X
authentication.
•
Perform MAC authentication: