Configuring Mac Authentication Delay; Displaying And Maintaining Mac Authentication - HP 10500 Series Configuration Manual

Security configuration guide
Hide thumbs Also See for 10500 Series:
Table of Contents

Advertisement

Feature
Port intrusion protection
If MAC authentication clients in your network cannot trigger an immediate DHCP-assigned IP address
renewal in response to a VLAN change, the MAC authentication users cannot access authorized network
resources immediately after a MAC authentication is complete. As a solution, remind the MAC
authentication users to release their IP addresses or repair their network connections for a DHCP
reassignment after MAC authentication is complete.
Before you configure a MAC authentication critical VLAN on a port, complete the following tasks:
Enable MAC authentication.
Enable MAC-based VLAN on the port.
Create the VLAN to be specified as the MAC authentication critical VLAN.
To configure a MAC authentication critical VLAN:
Step
1.
Enter system view.
2.
Enter Layer 2 Ethernet
interface view.
3.
Specify a MAC
authentication critical
VLAN.

Configuring MAC authentication delay

When both 802.1X authentication and MAC authentication are enabled on a port, you can delay MAC
authentication, so that 802.1X authentication is preferentially triggered.
The MAC authentication delay feature is available in Release 1208 and later versions.
To configure MAC authentication delay:
Step
1.
Enter system view.
2.
Enter Layer 2 Ethernet
interface view.
3.
Enable MAC authentication
delay and set the delay timer.

Displaying and maintaining MAC authentication

Relationship description
The MAC authentication critical VLAN function has
higher priority than the block MAC action but lower
priority than the shut down port action of the port
intrusion protection feature.
Command
system-view
interface interface-type
interface-number
mac-authentication critical vlan
critical-vlan-id
Command
system-view
interface interface-type
interface-number
mac-authentication timer
auth-delay time
117
Reference
See
"Configuring port
security."
Remarks
N/A
N/A
By default, no MAC authentication
critical VLAN is configured.
You can configure only one MAC
authentication critical VLAN on a
port.
Remarks
N/A
N/A
By default, MAC authentication
delay is disabled.

Advertisement

Table of Contents
loading

Table of Contents