Configuration Restrictions And Guidelines; Configuration Procedure; Ignoring Authorization Information From The Server; Enabling Mac Move - HPE FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Configuration restrictions and guidelines

On a port, the maximum number of MAC addresses in a VLAN cannot be smaller than the number of
existing MAC addresses in the VLAN. If the specified maximum number is smaller, the setting does
not take effect.

Configuration procedure

To set port security's limit on the number of MAC addresses for specific VLANs on a port:
Step
1.
Enter system view.
2.
Enter interface view.
3.
Set port security's limit on the
number of MAC addresses
for specific VLANs on the
port.

Ignoring authorization information from the server

You can configure a port to ignore the authorization information received from the server (local or
remote) after an 802.1X or MAC authentication user passes authentication.
To configure a port to ignore authorization information from the server:
Step
1.
Enter system view.
2.
Enter interface view.
3.
Ignore the authorization
information received from the
authentication server.

Enabling MAC move

MAC move allows 802.1X or MAC authenticated users to move between ports on a device. For
example, if an authenticated 802.1X user moves to another 802.1X-enabled port on the device, the
authentication session is deleted from the first port. The user is reauthenticated on the new port.
If MAC move is disabled, 802.1X or MAC users authenticated on one port cannot pass
authentication after they move to another port.
As a best practice, enable MAC move for users that roam between ports to access the network.
To enable MAC move:
Step
1.
Enter system view.
2.
Enable MAC move.
Command
system-view
interface interface-type
interface-number
port-security mac-limit
max-number per-vlan vlan-id-list
Command
system-view
interface interface-type
interface-number
port-security authorization
ignore
Command
system-view
port-security mac-move permit
250
Remarks
N/A
N/A
The default setting is
2147483647.
Remarks
N/A
N/A
By default, a port uses the
authorization information received
from the authentication server.
Remarks
N/A
By default, MAC move is
disabled.

Advertisement

Table of Contents
loading

Table of Contents