HP FlexNetwork NJ5000 User Manual page 371

5g poe+ walljack
Table of Contents

Advertisement

Advanced mode—Port security supports 802.1X and MAC authentication. Different port
security modes represent different combinations of the two methods.
Table 123
describes the advanced security modes.
Table 123 Advanced security modes
Advanced mode
MAC-Auth
802.1X Port Based
802.1X Single Host
802.1X MAC Based
802.1X MAC Based Or
OUI
MAC-Auth Or 802.1X
Single Host
MAC-Auth Or 802.1X
MAC Based
MAC-Auth Else 802.1X
Single Host
MAC-Auth Else 802.1X
MAC Based
The maximum number of users a port supports equals the maximum number of secure MAC
addresses that port security allows or the maximum number of concurrent users the authentication
mode in use allows, whichever is smaller.
An OUI is a 24-bit number that uniquely identifies a vendor, manufacturer, or organization. In MAC
addresses, the first three octets are the OUI.
Description
A port performs MAC authentication for users. It services multiple users.
A port performs 802.1X authentication and implements port-based access
control.
In this mode, a port can service multiple 802.1X users. If one 802.1X user
passes authentication, all the other 802.1X users of the port can access
the network without authentication.
In this mode, neither outbound restriction nor intrusion protection will be
triggered.
A port performs 802.1X authentication and implements MAC-based
access control. It services only one user passing 802.1X authentication.
A port performs 802.1X authentication of users and implements
MAC-based access control. The port in this mode supports multiple online
802.1X users.
Similar to the 802.1X Single Host mode, a port in this mode performs
802.1X authentication of users and allows only one 802.1X user to access
at a time.
The port also permits frames from a wired terminal whose MAC
address contains a specific OUI.
For frames from a wireless user, the port performs OUI check at first.
If the OUI check fails, the port performs 802.1X authentication.
This mode is the combination of the 802.1X Single Host and MAC-Auth
modes, with 802.1X authentication having higher priority.
For wired users, the port performs MAC authentication upon receiving
non-802.1X frames and performs 802.1X authentication upon
receiving 802.1X frames.
For wireless users, 802.1X authentication is performed first. If 802.1X
authentication fails, MAC authentication is performed.
Similar to the MAC-Auth Or 802.1X Single Host mode, except that it
supports multiple 802.1X and MAC authentication users on the port.
This mode is the combination of the MAC-Auth and 802.1X Single Host
modes, with MAC authentication having higher priority.
A port in this mode performs only MAC authentication for non-802.1X
frames.
For 802.1X frames, the port performs MAC authentication and then, if
MAC authentication fails, 802.1X authentication.
Similar to the MAC-Auth Else 802.1X Single Host mode, except that it
supports multiple 802.1X and MAC authentication users on the port.
359

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents