![Planet IGSW-2840 Скачать руководство пользователя страница 468](http://html1.mh-extra.com/html/planet/igsw-2840/igsw-2840_user-manual_1563287468.webp)
User’s Manual of IGSW-2840
468
max-mac-count
addresses on an interface
network-access dynamic-vlan
Enables dynamic VLAN assignment from a RADIUS server
IC
network-access guest-vlan
Specifies the guest VLAN
IC
mac-authentication reauth-time Sets the time period after which a connected MACaddress must
be re-authenticated
GC
clear network-access
Clears authenticated MAC addresses from the address table
PE
show network-access
Displays the MAC authentication settings for port interfaces
PE
show network-access
mac-address-table
Displays information for entries in the secure MAC address
table
PE
Table 5-42
Network Access
network-access mode
Use this command to enable network access authentication on a port. Use the no form of this command to disable network
access authentication.
Syntax
[no] network-access mode mac-authentication
Default Setting
Disabled
Command Mode
Interface Configuration
Command Usage
When enabled on a port, the authentication process sends a Password Authentication Protocol (PAP) request to a
configured RADIUS server. The username and password are both equal to the MAC address being authenticated.
On the RADIUS server, PAP usernames and passwords must be configured in the MAC address format
XX-XX-XX-XX-XX-XX (all in upper case).
Authenticated MAC addresses are stored as dynamic entries in the switch secure MAC address table and are removed
when the aging time expires. The maximum number of secure MAC addresses supported for the switch system is 1024.
Configured static MAC addresses are added to the secure address table when seen on a switch port. Static addresses are
treated as authenticated without sending a request to a RADIUS server.
MAC authentication, 802.1X, and port security cannot be configured together on the same port. Only one security
mechanism can be applied.
MAC authentication cannot be configured on trunk ports.
When port status changes to down, all MAC addresses are cleared from the secure MAC address table. Static VLAN
assignments are not restored.
The RADIUS server may optionally return a VLAN identifier list. VLAN identifier list is carried in the
“Tunnel-Private-Group-ID” attribute. The VLAN list can contain multiple VLAN identifiers in the format “1u,2t,” where “u”
indicates untagged VLAN and “t” tagged VLAN. The “Tunnel-Type” attribute should be set to “VLAN,” and the
“Tunnel-Medium-Type” attribute set to “802.”
Содержание IGSW-2840
Страница 23: ...User s Manual of IGSW 2840 23 A 2 10 100Mbps 10 100Base TX 665 APPENDEX B GLOSSARY 667 ...
Страница 110: ...User s Manual of IGSW 2840 110 Figure 4 3 14 SNMPv3 View Edit screenshot ...
Страница 119: ...User s Manual of IGSW 2840 119 Figure 4 4 7 Mirror Port Configuration screenshot ...
Страница 205: ...User s Manual of IGSW 2840 205 Multicast Service Multicast flooding ...
Страница 216: ...User s Manual of IGSW 2840 216 Figure 4 9 7 IGMP Member Port Table screenshot ...
Страница 280: ...User s Manual of IGSW 2840 280 Figure 4 11 19 SSH Host Key Settings screenshot ...
Страница 315: ...User s Manual of IGSW 2840 315 Figure 4 11 44 MAC ACL Settings screenshot ...
Страница 317: ...User s Manual of IGSW 2840 317 Figure 4 11 46 ACL Port Binding Settings screenshot ...
Страница 431: ...User s Manual of IGSW 2840 431 tacacs 1 Console ...