Enabling The Mac Authentication Critical Voice Vlan; Configuration Prerequisites - HPE FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Create the VLAN to be specified as the MAC authentication critical VLAN.
Configure the VLAN as an untagged member on the port.
When you configure the MAC authentication critical VLAN on a port, follow the guidelines in
15.
Table 15 Relationships of the MAC authentication critical VLAN with other security features
Feature
Quiet feature of MAC
authentication
Super VLAN
Port intrusion protection
To configure the MAC authentication critical VLAN on a port:
Step
1.
Enter system view.
2.
Enter interface view.
3.
Specify the MAC
authentication critical
VLAN on the port.
Enabling the MAC authentication critical voice
VLAN
The MAC authentication critical voice VLAN on a port accommodates MAC authentication voice
users that have failed authentication because none of the RADIUS servers in their ISP domain are
reachable.

Configuration prerequisites

Before you enable the MAC authentication critical voice VLAN on a port, complete the following
tasks:
Enable LLDP both globally and on the port.
The device uses LLDP to identify voice users. For information about LLDP, see Layer 2—LAN
Switching Configuration Guide.
Enable voice VLAN on the port.
Relationship description
The MAC authentication critical VLAN feature has
higher priority.
When a user fails MAC authentication because no
RADIUS authentication server is reachable, the
user can access the resources in the critical
VLAN. The user's MAC address is not marked as
a silent MAC address.
You cannot specify a VLAN as both a super VLAN
and a MAC authentication critical VLAN.
The critical VLAN feature has higher priority than
the block MAC action but lower priority than the
shutdown port action of the port intrusion
protection feature.
Command
system-view
interface interface-type
interface-number
mac-authentication critical vlan
critical-vlan-id
151
Reference
See
"Configuring MAC
authentication
timers."
See Layer 2—LAN
Switching Configuration
Guide.
See
"Configuring port
security."
Remarks
N/A
N/A
By default, no MAC authentication
critical VLAN exists.
You can configure only one MAC
authentication critical VLAN on a
port.
Table

Advertisement

Table of Contents
loading

Table of Contents