
Configuring Universal Network Profiles
Configuring UNP Port-Based Access Control
OmniSwitch AOS Release 7 Network Configuration Guide
June 2013
page 27-29
By default, the UNP port type is set to bridge when UNP is enabled on the port. To configure the port
type, use the
command. For example:
-> unp port 1/12 port-type access
-> unp linkagg 5 port-type access
If UNP is not enabled on the specified port or link aggregate, the unp port-type will enable UNP function-
ality at the same time the port type is configured.
Note.
To change the port type of an existing UNP port, remove the current UNP configuration first using
the
no unp port
or
no unp linkagg
command then use the
unp port-type
command to set the new port
type.
-> no unp port 1/12
-> unp port 1/12 port-type bridge
-> no unp linkagg 5
-> unp linkagg 5 port-type bridge
Configuring UNP Port Parameters
Enabling UNP functionality on a switch port does not automatically enable authentication and classifica-
tion for traffic on that port. Configuration of additional port parameters is required to define the device
classification options that the switch will apply to non-supplicant traffic received on the UNP port.
The configuration of UNP port parameters described in this section is only allowed on UNP-enabled
switch ports. Make sure UNP is enabled first before attempting to configure any UNP port parameters.
Note.
Any configuration change to a UNP-enabled port will flush all MAC addresses learned on that port.
This applies only to CLI commands used to configure UNP port parameters.
Enabling MAC Authentication
By default, when UNP is enabled on the port, MAC authentication is disabled. This means that the source
MAC address of devices connected to the port are not sent to the RADIUS server for identification and
authentication. Instead, other classification parameters configured for the port are applied first.
When MAC authentication is enabled on the UNP port, authentication takes precedence over all other
classification parameters configured for the port. If a device fails MAC authentication, then additional
classification methods configured for the port are applied.
To enable MAC authentication for the UNP port, use the
command with the
enable
option.
-> unp port 1/10 mac-authentication enable
-> unp port 1/15-20 mac-authentication enable
To disable MAC authentication, use the
unp port mac-authentication
command with the
disable
option.
-> unp port 1/10 mac-authentication disable
-> unp port 1/15-20 mac-authentication disable
Содержание os6900
Страница 28: ...Contents xxviii OmniSwitch AOS Release 7 Network Configuration Guide June 2013...
Страница 374: ...VRF Route Leak Configuring IP page 15 40 OmniSwitch AOS Release 7 Network Configuration Guide June 2013...
Страница 692: ...Policy Applications Configuring QoS page 25 84 OmniSwitch AOS Release 7 Network Configuration Guide June 2013...