Command Line Interface
4-152
4
network-access mode
Use this command to enable network access authentication on a port. Use the
no
form of this command to disable network access authentication.
Syntax
[
no
]
network-access mode mac-authentication
Default Setting
Disabled
Command Mode
Interface Configuration
Command Usage
• When enabled on a port, the authentication process sends a Password
Authentication Protocol (PAP) request to a configured RADIUS server. The
username and password are both equal to the MAC address being
authenticated.
• On the RADIUS server, PAP username and passwords must be configured in
the MAC address format XX-XX-XX-XX-XX-XX (all in upper case).
• Authenticated MAC addresses are stored as dynamic entries in the switch
secure MAC address table and are removed when the aging time expires. The
maximum number of secure MAC addresses supported for the switch system
is 1024.
• Configured static MAC addresses are added to the secure address table
when seen on a switch port. Static addresses are treated as authenticated
without sending a request to a RADIUS server.
• MAC authentication, 802.1X, and port security cannot be configured together
on the same port. Only one security mechanism can be applied.
• MAC authentication cannot be configured on trunk ports.
• When port status changes to down, all MAC addresses are cleared from the
secure MAC address table. Static VLAN assignments are not restored.
• The RADIUS server may optionally return a VLAN identifier list. VLAN
identifier list is carried in the “Tunnel-Private-Group-ID” attribute. The VLAN
list can contain multiple VLAN identifiers in the format “1u,2t,” where “u”
indicates untagged VLAN and “t” tagged VLAN. The “Tunnel-Type” attribute
should be set to “VLAN,” and the “Tunnel-Medium-Type” attribute set to “802.”
Example
Console(config-if)#network-access mode mac-authentication
Console(config-if)#
Содержание iES4028F
Страница 1: ...iES4028F 4028FP 4024GP ...
Страница 2: ...iES4028F iES4028FP iES4024GP E082008 ST R03 149100041800A 149100040200A 149100041700A 149100000020A ...
Страница 4: ...iv This page is intentionally left blank ...
Страница 10: ...x This page is intentionally left blank ...
Страница 28: ...Contents xxviii This page is intentionally left blank ...
Страница 32: ...Tables xxxii This page is intentionally left blank ...
Страница 46: ...Introduction 1 10 1 This page is intentionally left blank ...
Страница 336: ...Configuring the Switch 3 280 3 This page is intentionally left blank ...
Страница 688: ...Command Line Interface 4 352 4 This page is intentionally left blank ...
Страница 702: ...Glossary Glossary 8 This page is intentionally left blank ...
Страница 710: ...Index 8 Index This page is intentionally left blank ...
Страница 711: ...This page is intentionally left blank ...
Страница 712: ...iES4028F 4028FP 4024GP ...