Ignoring Authorization Information From The Server; Enabling Mac Move; Enabling The Authorization-Fail-Offline Feature - HPE FlexNetwork 7500 Series Security Configuration Manual

Table of Contents

Advertisement

Step
4.
Enter interface view.
5.
(Optional.) Enable
inactivity aging.
6.
(Optional.) Enable the
dynamic secure MAC
feature.

Ignoring authorization information from the server

You can configure a port to ignore the authorization information received from the server (local or
remote) after an 802.1X or MAC authentication user passes authentication.
To configure a port to ignore authorization information from the server:
Step
1.
Enter system view.
2.
Enter interface view.
3.
Ignore the authorization
information received from the
authentication server.

Enabling MAC move

MAC move allows 802.1X or MAC authenticated users to move between ports on a device. For
example, if an authenticated 802.1X user moves to another 802.1X-enabled port on the device, the
authentication session is deleted from the first port. The user is reauthenticated on the new port.
If MAC move is disabled, 802.1X or MAC users authenticated on one port cannot pass
authentication after they move to another port.
As a best practice, enable MAC move for users that roam between ports to access the network.
To enable MAC move:
Step
1.
Enter system view.
2.
Enable MAC move.

Enabling the authorization-fail-offline feature

The authorization-fail-offline feature logs off port security users who fail ACL authorization.
Command
vlan vlan-id
c. quit
interface interface-type
interface-number
port-security mac-address
aging-type inactivity
port-security mac-address dynamic
Command
system-view
interface interface-type
interface-number
port-security authorization
ignore
Command
system-view
port-security mac-move permit
233
Remarks
N/A
By default, the inactivity aging
feature is disabled.
By default, the dynamic secure
MAC feature is disabled. Sticky
MAC addresses can be saved to
the configuration file. Once saved,
they can survive a device reboot.
Remarks
N/A
N/A
By default, a port uses the
authorization information received
from the authentication server.
Remarks
N/A
By default, MAC move is
disabled.

Advertisement

Table of Contents
loading

Table of Contents