Client Security
3-99
3
Configuring MAC Authentication for Ports
Configures MAC authentication on switch ports, including setting the maximum MAC
count, applying a MAC address filter, and enabling dynamic VLAN assignment.
Command Attributes
•
Mode
– Enables MAC authentication on a port. (Default: None)
•
Maximum MAC Count
– Sets the maximum number of MAC addresses that can
be authenticated on a port. The maximum number of MAC addresses per port is
2048, and the maximum number of secure MAC addresses supported for the
switch system is 1024. When the limit is reached, all new MAC addresses are
treated as an authentication failure. (Range: 1-1024; Default: 1024)
•
Guest VLAN
– Specifies the VLAN to be assigned to the port when MAC
Authentication through 802.1X fails. (Default: Disabled; Range: 1-4094)
The VLAN must already be created and active (see “Creating VLANs” on page
3-174). Also, when used with 802.1X authentication, intrusion action must be set
for “Guest VLAN” (see “Configuring Port Settings for 802.1X” on page 3-83).
•
Dynamic VLAN
– Enables dynamic VLAN assignment for an authenticated port.
When enabled, any VLAN identifiers returned by the RADIUS server are applied to
the port, providing the VLANs have already been created on the switch. (GVRP is
not used to create the VLANs.) (Default: Enabled)
The VLAN settings specified by the first authenticated MAC address are
implemented for a port. Other authenticated MAC addresses on the port must have
the same VLAN configuration, or they are treated as authentication failures.
If dynamic VLAN assignment is enabled on a port and the RADIUS server returns
no VLAN configuration, the authentication is still treated as a success, and the host
assigned to the default untagged VLAN.
When the dynamic VLAN assignment status is changed on a port, all authenticated
addresses are cleared from the secure MAC address table.
Note:
MAC authentication cannot be configured on trunk ports. Ports configured as trunk
members are indicated on the in the “Trunk” column.
Содержание JetNet 5228G Series
Страница 3: ...www edge core com 2 24FE 4G Layer 2 4 Ethernet Switch Management Guide V1 1...
Страница 24: ...Tables xx...
Страница 310: ...Configuring the Switch 3 264 3...
Страница 636: ...Command Line Interface 4 326 4...
Страница 650: ...Glossary Glossary 8...
Страница 656: ...Index 6 Index...
Страница 657: ......
Страница 658: ......