Configuration Restrictions And Guidelines; Configuration Procedure; Configuring A Mac Authentication Critical Vlan - HPE FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Enable MAC authentication globally and on the port.
Enable MAC-based VLAN on the port.
Create the VLAN to be specified as the MAC authentication guest VLAN.
Configure the VLAN as an untagged member on the port.

Configuration restrictions and guidelines

The following table shows the relationships of the MAC authentication guest VLAN with other
security features:
.
Feature
Quiet feature of MAC
authentication
Super VLAN
Port intrusion protection

Configuration procedure

To configure the MAC authentication guest VLAN on a port:
Step
1.
Enter system view.
2.
Enter interface view.
3.
Specify the MAC
authentication guest
VLAN on the port.
4.
(Optional.) Set the
authentication interval
for users in the MAC
authentication guest
VLAN.

Configuring a MAC authentication critical VLAN

You must configure the MAC authentication critical VLAN on a hybrid port. Before you configure the
MAC authentication critical VLAN on a hybrid port, complete the following tasks:
Enable MAC authentication globally and on the port.
Enable MAC-based VLAN on the port.
Relationship description
The MAC authentication guest VLAN
feature has higher priority.
When a user fails MAC authentication, the
user can access the resources in the guest
VLAN. The user's MAC address is not
marked as a silent MAC address.
You cannot specify a VLAN as both a super
VLAN and a MAC authentication guest
VLAN.
The guest VLAN feature has higher priority
than the block MAC action but lower priority
than the shutdown port action of the port
intrusion protection feature.
Command
system-view
interface interface-type
interface-number
mac-authentication
guest-vlan guest-vlan-id
mac-authentication
guest-vlan auth-period
period-value
150
Reference
See
"Configuring MAC
authentication
timers."
See Layer 2—LAN Switching
Configuration Guide.
See
"Configuring port
Remarks
N/A
N/A
By default, no MAC authentication guest
VLAN exists.
You can configure only one MAC
authentication guest VLAN on a port.
The default setting is 30 seconds.
security."

Advertisement

Table of Contents
loading

Table of Contents