Configuring The Keep-Online Feature - HP FlexFabric 5700 Series Security Configuration Manual

Hide thumbs Also See for FlexFabric 5700 Series:
Table of Contents

Advertisement

Table 13 Relationships of the MAC authentication critical VLAN with other security features
Feature
Quiet feature of MAC
authentication
Port intrusion protection
To configure the MAC authentication critical VLAN on a port:
Step
1.
Enter system view.
2.
Enter Layer 2 Ethernet
interface view.
3.
Specify the MAC
authentication critical
VLAN on the port.

Configuring the keep-online feature

By default, the device logs off online MAC authentication users if no server is reachable for MAC
reauthentication. The keep-online feature keeps authenticated MAC authentication users online when no
server is reachable for MAC reauthentication.
In a fast-recovery network, you can use the keep-online feature to prevent MAC authentication users from
coming online and going offline frequently.
To configure the keep-online feature:
Step
1.
Enter system view.
2.
Enter Layer 2 Ethernet interface
view.
3.
Enable the keep-online feature
for authenticated MAC
authentication users on the port.
Relationship description
The MAC authentication critical VLAN feature has
higher priority.
When a user fails MAC authentication because no
RADIUS authentication server is reachable, the user
can access the resources in the critical VLAN. The
user's MAC address is not marked as a silent MAC
address.
The critical VLAN feature has higher priority than
the block MAC action but lower priority than the
shutdown port action of the port intrusion
protection feature.
Command
system-view
interface interface-type
interface-number
mac-authentication critical vlan
critical-vlan-id
Command
system-view
interface interface-type
interface-number
mac-authentication re-authenticate
server-unreachable keep-online
110
Reference
See
"Setting MAC
authentication
timers."
See
"Configuring port
security."
Remarks
N/A
N/A
By default, no MAC authentication
critical VLAN is configured.
You can configure only one MAC
authentication critical VLAN on a
port.
Remarks
N/A
N/A
By default, the keep-online
feature is disabled.
This command takes effect only
when the authentication server
assigns reauthentication
attributes to the device.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents