Configuration Guide
802.1x Configuration
Configuring Multiple MAB Authentication Function
When there are multiple devices without authentication clients under one port need to access the 802.1x authentication,
MAC Authentication Bypass (MAB) of a single user cannot meet the requirements. The multiple MAB authentication
function is developed under such a context. After the multiple MAB authentication function is enabled, the device will send
the MAC address learned under the port as the username and password to the server for authentication. If passing the
authentication, the device can access the network normally; otherwise, it cannot access the network.
Use the following commands to configure the multiple MAB authentication function.
Command
Function
Ruijie(config)#
interface
interface-id
Enters interface configuration mode.
Ruijie(config-if)#
dot1x
mac
-
auth
-
bypass multi-user
Enables the multiple MAB authentication function.
Ruijie#
show
running
-
config
Shows all configurations.
This example shows how to configure the multiple MAB authentication function.The online time of MAB
users supported by multiple MAB users is the time configured by the
dot1x mac-auth-bypass
timeout-activity <value>
command.
0
indicates that the user can be online all the time. In addition, users
with multiple MAB support the server to deliver the value of the
session_timeout
parameter. When the users
log out depends on which of the two time values runs out first.
The multiple MAB authentication only supports mac-based authentication. If the authentication mode of the
port is set to port-based, the multiple MAB authentication mode cannot be configured and take effect.
Conversely, if the multiple MAB authentication function is enabled but the authentication mode of the port
cannot be changed, you must disable the multiple MAB authentication function first.
Multiple MAB authentication and single MAB authentication are mutual exclusive to each other in function.
You can configure only one mode at the same time.
Multiple MAB authentication can coexist with the dot1x authentication. If a MAC address performs the dot1x
authentication first, the address will not perform the multiple MAB authentication. If a MAC address performs
the multiple MAB authentication first, and then performs the authentication by the client, the multiple MAB
authentication user will log out first, and then performs the dot1x authentication.
If a fail VLAN is configured, when the failure times of authentication of multiple MAB user reaches the failure
attempt time, fail VLAN authorization is performed. If the port for authorization is a Hybrid port and
configured with the mac vlan function, the mac vlan authorization is performed; otherwise, the port vlan
authorization is performed.
Содержание RG-S2900G-E Series
Страница 1: ...RG S2900G E Series Switch RGOS Configuration Guide Release 10 4 2b12 p1 ...
Страница 91: ...Configuration Guide Configuring PoE Configuration ...
Страница 133: ...Configuration Guide EEE Configuration ...
Страница 319: ...Configuration Guide QinQ Configuration ...
Страница 408: ......
Страница 409: ...IP Routing Configuration 1 Static Route Configuration ...
Страница 412: ......
Страница 413: ...Multicast Configuration 1 IGMP Snooping Configuration 2 MLD Snooping Configuration ...
Страница 621: ...Configuration Guide CPU Protection Configuration udp helper 180 4 dhcp client 180 4 lacp 180 4 ...
Страница 757: ......
Страница 758: ...ACL QoS Configuration 1 Access Control List Configuration 2 QoS Configuration ...
Страница 801: ...Reliability Configuration 1 RLDP Configuration 2 TPP Configuration 3 SEM Configuration ...
Страница 901: ...Configuration Guide ERSPAN Configuration ...
Страница 902: ...Web based Configuration 1 Web based Configuration ...