Macaddresselseuserloginsecure Configuration Example - HP 5920 Series Configuration Manual

Hide thumbs Also See for 5920 Series:
Table of Contents

Advertisement

Access-limit: Disabled
Access-Count: 0
lan-access Authentication Scheme:
lan-access Authorization
lan-access Accounting
default Authentication Scheme:
default Authorization
default Accounting
# Display the port security configuration.
[Device] display port-security interface ten-gigabitethernet 1/0/1
Port security is enabled globally
AutoLearn aging time is 0 minutes
Disableport Timeout: 20s
OUI value:
Index is 1,
Index is 2,
Index is 3,
Index is 4,
Index is 5,
Ten-GigabitEthernet1/0/1 is link-up
Port mode : userLoginWithOUI
NeedToKnow mode: Disabled
Intrusion protection mode: NoAction
Max number of secure MAC addresses: Not configured
Current number of secure MAC addresses: 1
Authorization is permitted
After an 802.1X user goes online, you can see that the number of secure MAC addresses saved by the
port is 1. You can use the display dot1x command to display information about online 802.1X users.
The port also allows one user whose MAC address has an OUI among the specified OUIs to pass
authentication. You can use the following command to display the MAC address information for the port:
[Device] display mac-address interface ten-gigabitethernet 1/0/1
MAC Address
1234-0300-0011

macAddressElseUserLoginSecure configuration example

Network requirements
As shown in
authenticates the client by a RADIUS server. If the authentication succeeds, the client is authorized to
access the Internet.
Restrict port Ten-GigabitEthernet 1/0/1 of the device as follows:
Allow more than one MAC authenticated user to log on.
For 802.1X users, perform MAC authentication first and then, if MAC authentication fails, 802.1X
authentication. Allow only one 802.1X user to log on.
Scheme:
Scheme:
Scheme:
Scheme:
OUI value is 123401
OUI value is 123402
OUI value is 123403
OUI value is 123404
OUI value is 123405
VLAN ID
State
1
Learned
Figure
67, a client is connected to the device through Ten-GigabitEthernet 1/0/1. The device
radius: radsun
radius: radsun
radius: radsun
local
local
local
Port
Ten-GigabitEthernet1/0/1
159
Aging
Y

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

5900 series

Table of Contents