HP MSR Series Command Reference Manual page 218

Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

Keyword
userlogin
userlogin-secure
userlogin-secure-ext
userlogin-secure-or-mac
userlogin-secure-or-mac
-ext
userlogin-withoui
Usage guidelines
To change the security mode of a port security enabled port, you must set the port in noRestrictions mode
first. When the port has online users, you cannot change port security mode.
IMPORTANT:
If you are configuring the autoLearn mode, first set port security's limit on the number of secure MAC
addresses by using the port-security max-mac-count command. You cannot change the setting when the
port is operating in autoLearn mode.
When port security is enabled, you cannot enable 802.1X or MAC authentication, or change the access
control mode or port authorization state. The port security automatically modifies these settings in
different security modes.
HP recommends that you do not enable the mac-else-userlogin-secure or mac-else-userlogin-secure-ext
mode on the port where the MAC authentication delay is enabled. The two modes are mutually exclusive
Security mode
userLogin
userLoginSecure
userLoginSecureExt
macAddressOrUserL
oginSecure
macAddressOrUserL
oginSecureExt
userLoginWithOUI
204
Description
In this mode, a port performs 802.1X authentication and
implements port-based access control.
If one 802.1X user passes authentication, all the other
802.1X users of the port can access the network without
authentication.
In this mode, a port performs 802.1X authentication and
implements MAC-based access control. the port services
only one user passing 802.1X authentication.
Same as the userLoginSecure mode, except that this mode
supports multiple online 802.1X users.
This mode is the combination of the userLoginSecure and
macAddressWithRadius modes. In this mode, the port
allows one 802.1X authentication user and multiple MAC
authentication users to log in.
For wired users, the port performs MAC authentication
upon receiving non-802.1X frames and performs
802.1X authentication upon receiving 802.1X frames.
For wireless users, the port performs 802.1X
authentication first. If 802.1X authentication fails, MAC
authentication is performed.
Same as the macAddressOrUserLoginSecure mode,
except that a port in this mode supports multiple 802.1X
and MAC authentication users.
Similar to the userLoginSecure mode. In addition, a port in
this mode also permits frames from a user whose MAC
address contains a specific OUI.
For wired users, the port performs 802.1X
authentication upon receiving 802.1X frames, and
performs an OUI check upon receiving non-802.1X
frames.
For wireless users, the port performs an OUI check at
first. If the OUI check fails, the port performs 802.1X
authentication.

Advertisement

Table of Contents
loading

Table of Contents