Configuring The Userloginwithoui Mode - HP 6600 Security Configuration Manual

Table of Contents

Advertisement

#
Perform the display port-security interface command after the number of MAC addresses learned by the
port reaches 64, and you can see that the port security mode has changed to secure. When any frame
with a new MAC address arrives, intrusion protection is triggered and you can see the following trap
message:
#Jul 14 10:39:47:135 2009 Router PORTSEC/4/VIOLATION: -Slot=3; Trap1.3.6.1.4.1.255
06.2.26.1.3.2<hh3cSecureViolatio
An intrusion occurs!
IfIndex: 9437185
Port: 9437185
MAC Addr: 00:02:00:00:00:32
VLAN ID: 1
IfAdminStatus: 1
# Execute the display interface command, and you can see that the port security feature has disabled the
port.
[Router-GigabitEthernet3/0/1] display interface gigabitethernet 3/0/1
GigabitEthernet3/0/1 current state: DOWN (Port Security Disabled)
IP Packet Frame Type: PKTFMT_ETHNT_2, Hardware Address: 000f-cb00-5558
Description: GigabitEthernet3/0/1 Interface
......
The port should be re-enabled 30 seconds later.
[Router-GigabitEthernet3/0/1] display interface gigabitethernet 3/0/1
GigabitEthernet3/0/1 current state: UP
IP Packet Frame Type: PKTFMT_ETHNT_2, Hardware Address: 000f-cb00-5558
Description: GigabitEthernet3/0/1 Interface
......
Delete several secure MAC addresses, and you can see that the port security mode of the port changes
to autoLearn, and the port can learn MAC addresses again.

Configuring the userLoginWithOUI mode

Network requirements
As shown in
Router authenticates the client with a RADIUS server. If the authentication succeeds, the client is
authorized to access the Internet.
The RADIUS server at 192.168.1.2 functions as the primary authentication server and the secondary
accounting server, and the RADIUS server at 192.168.1.3 functions as the secondary authentication
server and the primary accounting server. The shared key for authentication is name, and that for
accounting is money.
All users use the default authentication, authorization, and accounting methods of ISP domain sun,
which can accommodate up to 30 users.
The RADIUS server response timeout time is 5 seconds and the maximum number of RADIUS packet
retransmission attempts is 5. The Router sends real-time accounting packets to the RADIUS server at
15–minute intervals, and sends usernames without domain names to the RADIUS server.
Configure port GigabitEthernet 3/0/1 of the Router to:
Allow only one 802.1X user to be authenticated.
Figure
77, a client is connected to the Router through port GigabitEthernet 3/0/1. The
190

Advertisement

Table of Contents
loading

This manual is also suitable for:

Hsr6600

Table of Contents