Specifying An Authentication Domain For Mac Authentication Users - HP A5830 Series Configuration Manual

Security switch
Hide thumbs Also See for A5830 Series:
Table of Contents

Advertisement

To do...
4.
Configure the properties
of MAC authentication
user accounts.
When global MAC authentication is enabled, the EAD fast deployment function cannot take effect.
Configuring MAC authentication on a port
To do...
1.
Enter system view.
2.
Enable MAC
authentication.
3.
Set the maximum number of
concurrent MAC authentication
users allowed on a port.
You cannot add a MAC authentication enabled port in to a link aggregation group or enable MAC
authentication on a port already in a link aggregation group.
Specifying an authentication domain for MAC
authentication users
By default, MAC authentication users are in the system default authentication domain. To implement
different access policies for users, you can specify authentication domains for MAC authentication users
in the following ways:
Specify a global authentication domain in system view. This domain setting applies to all ports.
Specify an authentication domain for an individual port in Ethernet interface view.
MAC authentication chooses an authentication domain for users on a port in this order: the interface-
specific domain, the global domain, and the default domain. For more information about authentication
domains, see "
To specify an authentication domain for MAC authentication users:
To do...
1.
Enter system view.
2.
Specify an authentication
domain for MAC
Use the command...
mac-authentication user-name-format
{ fixed [ account name ] [ password {
cipher | simple } password ] | mac-
address [ { with-hyphen | without-
hyphen } [ lowercase | uppercase ] ] }
In system view
In Ethernet
interface view
C onfiguring
AAA."
3
Use the command...
system-view
mac-authentication domain domain-
name
Use the command...
system-view
mac-authentication interface
interface-list
interface interface-type interface-
number
mac-authentication
mac-authentication max-user
user-number
99
Remarks
Optional.
By default, the username and
password for a MAC
authentication user account must
be a MAC address in lowercase
characters without hyphens.
Remarks
Required.
Disabled by default.
Enable MAC authentication for
ports in bulk in system view or
an individual port in Ethernet
interface view.
Optional.
By default, the maximum
number of concurrent MAC
authentication users is 1024.
Remarks
Required

Advertisement

Table of Contents
loading

Table of Contents