Chapter 9
| General Security Measures
Network Access (MAC Address Authentication)
– 263 –
◆
Configured static MAC addresses are added to the secure address table
when seen on a switch port. Static addresses are treated as authenticated
without sending a request to a RADIUS server.
◆
MAC authentication, 802.1X, and port security cannot be configured
together on the same port. Only one security mechanism can be applied.
◆
MAC authentication cannot be configured on trunks (i.e., static nor
dynamic).
◆
When port status changes to down, all MAC addresses are cleared from
the secure MAC address table. Static VLAN assignments are not restored.
◆
The RADIUS server may optionally return a VLAN identifier list. VLAN
identifier list is carried in the “Tunnel-Private-Group-ID” attribute. The
VLAN list can contain multiple VLAN identifiers in the format “1u,2t,” where
“u” indicates untagged VLAN and “t” tagged VLAN. The “Tunnel-Type”
attribute should be set to “VLAN,” and the “Tunnel-Medium-Type” attribute
set to “802.”
Example
Console(config-if)#network-access mode mac-authentication
Console(config-if)#
network-access port-
mac-filter
Use this command to enable the specified MAC address filter. Use the
no
form of this command to disable the specified MAC address filter.
Syntax
network-access port-mac-filter
filter-id
no network-access port-mac-filter
filter-id
- Specifies a MAC address filter table. (Range: 1-64)
Default Setting
None
Command Mode
Interface Configuration
Command Mode
◆
Entries in the MAC address filter table can be configured with the
command.
◆
Only one filter table can be assigned to a port.
Содержание SC30010
Страница 1: ...C 300 Series Gigabit Managed Switch CLI Reference Guide SOFTWARE RELEASE V1 1 10 171 www signamax com ...
Страница 2: ...CLI Reference Guide SC30010 C 300 48 Port Gigabit Managed Switch E122017 KS R01 ...
Страница 482: ...Chapter 19 Class of Service Commands Priority Commands Layer 3 and 4 482 ...
Страница 670: ......
Страница 671: ...E122017 KS R01 ...