Specifying A Mac Authentication Domain; Configuring A Mac Authentication Guest Vlan - HP 10500 Series Configuration Manual

Security configuration guide
Hide thumbs Also See for 10500 Series:
Table of Contents

Advertisement

Step
3.
Set the maximum number of
concurrent MAC authentication
users allowed on a port.
NOTE:
When both (and only both) 802.1X authentication and MAC authentication are enabled on a port, the
device performs 802.1X authentication for 802.1X users that first access the network from the port.
Non-802.1X packets trigger MAC authentication.

Specifying a MAC authentication domain

By default, MAC authentication users are in the system default authentication domain. To implement
different access policies for users, you can specify authentication domains for MAC authentication users
in the following ways:
Specify a global authentication domain in system view. This domain setting applies to all ports.
Specify an authentication domain for an individual port in interface view.
MAC authentication chooses an authentication domain for users on a port in this order: the port-specific
domain, the global domain, and the default domain. For more information about authentication
domains, see
To specify an authentication domain for MAC authentication users:
Step
1.
Enter system view.
2.
Specify an authentication
domain for MAC
authentication users.

Configuring a MAC authentication guest VLAN

Follow the guidelines in
Table 8 Relationships of the MAC authentication guest VLAN with other security features
Feature
Quiet function of MAC
authentication
Super VLAN
"Configuring
AAA."
Command
system-view
(Approach 1) In system view:
mac-authentication domain
domain-name
(Approach 2) In interface view:
Table 8
when configuring a MAC authentication guest VLAN on a port.
Relationship description
The MAC authentication guest VLAN function
has higher priority. A user can access any
resources in the guest VLAN.
You cannot specify a VLAN as both a super
VLAN and a MAC authentication guest VLAN.
Command
mac-authentication max-user
user-number
a.
interface interface-type
interface-number
b.
mac-authentication domain
domain-name
115
Remarks
Optional.
The default is 1024.
Remarks
N/A
Use either approach.
By default, the system default
authentication domain is used for
MAC authentication users.
Reference
See
"MAC authentication
timers."
See Layer 2
LAN Switching
Configuration Guide.

Advertisement

Table of Contents
loading

Table of Contents