Network-access mode – PLANET SGSD-1022 User Manual

Page 478

Advertising
background image

User’s Manual of SGSD-1022 / SGSD-1022P

SGSW-2840 / SGSW-2840P

network-access

max-mac-count

Sets a maximum for authenticated MAC addresses on an

interface

IC

mac-authentication

intrusion-action

Determines the port response when a connected host fails MAC

authentication.

IC

mac-authentication

max-mac-count

Sets a maximum for mac-authentication autenticated MAC

addresses on an interface

IC

network-access dynamic-vlan

Enables dynamic VLAN assignment from a RADIUS server

IC

network-access guest-vlan

Specifies the guest VLAN

IC

mac-authentication reauth-time Sets the time period after which a connected MACaddress must

be re-authenticated

GC

clear network-access

Clears authenticated MAC addresses from the address table

PE

show network-access

Displays the MAC authentication settings for port interfaces

PE

show network-access

mac-address-table

Displays information for entries in the secure MAC address

table

PE

Table 5-42 Network Access

network-access mode

Use this command to enable network access authentication on a port. Use the no form of this command to disable network

access authentication.

Syntax

[no] network-access mode mac-authentication

Default Setting

Disabled

Command Mode

Interface Configuration

Command Usage

When enabled on a port, the authentication process sends a Password Authentication Protocol (PAP) request to a

configured RADIUS server. The username and password are both equal to the MAC address being authenticated.

On the RADIUS server, PAP usernames and passwords must be configured in the MAC address format

XX-XX-XX-XX-XX-XX (all in upper case).

Authenticated MAC addresses are stored as dynamic entries in the switch secure MAC address table and are removed

when the aging time expires. The maximum number of secure MAC addresses supported for the switch system is 1024.

Configured static MAC addresses are added to the secure address table when seen on a switch port. Static addresses are

treated as authenticated without sending a request to a RADIUS server.

MAC authentication, 802.1X, and port security cannot be configured together on the same port. Only one security

mechanism can be applied.

MAC authentication cannot be configured on trunk ports.

When port status changes to down, all MAC addresses are cleared from the secure MAC address table. Static VLAN

478

Advertising
This manual is related to the following products: