H3C S5120-EI Series Operation Manual page 676

Hide thumbs Also See for S5120-EI Series:
Table of Contents

Advertisement

[Sysname] acl number 3000
[Sysname-acl-adv-3000] rule 0 deny ip destination 10.0.0.1 0
[Sysname-acl-adv-3000] quit
# Enable MAC authentication globally.
[Sysname] mac-authentication
# Specify the ISP domain for MAC authentication users.
[Sysname] mac-authentication domain 2000
# Specify the MAC authentication username type as MAC address, that is, using the MAC address of a
user as the username and password for MAC authentication of the user.
[Sysname] mac-authentication user-name-format mac-address
# Enable MAC authentication for port GigabitEthernet 1/0/1.
[Sysname] interface GigabitEthernet 1/0/1
[Sysname-GigabitEthernet1/0/1] mac-authentication
After completing the above configurations, you can use the ping command to verify whether the ACL
3000 assigned by the RADIUS server functions.
[Sysname] ping 10.0.0.1
PING 10.0.0.1: 56
Request time out
Request time out
Request time out
Request time out
Request time out
--- 10.0.0.1 ping statistics ---
5 packet(s) transmitted
0 packet(s) received
100.00% packet loss
data bytes, press CTRL_C to break
1-10

Advertisement

Chapters

Table of Contents
loading

Table of Contents