Enabling Mac Move; Enabling The Authorization-Fail-Offline Feature; Applying A Nas-Id Profile To Port Security - HPE FlexNetwork 7500 Series Security Configuration Manual

Table of Contents

Advertisement

Enabling MAC move

MAC move allows 802.1X or MAC authenticated users to move between ports on a device. For
example, if an authenticated 802.1X user moves to another 802.1X-enabled port on the device, the
authentication session is deleted from the first port. The user is reauthenticated on the new port.
If MAC move is disabled and an 802.1X authenticated user moves to another port, the user is not
reauthenticated.
As a best practice, enable MAC move for wireless users that roam between ports to access the
network.
To enable MAC move:
Step
1.
Enter system view.
2.
Enable MAC move.

Enabling the authorization-fail-offline feature

The authorization-fail-offline feature logs off port security users who fail ACL authorization.
A user fails ACL authorization in the following situations:
The device fails to authorize the specified ACL to the user.
The server assigns a nonexistent ACL to the user.
This feature does not apply to users who fail VLAN authorization. The device logs off these users
directly.
To enable the authorization-fail-offline feature:
Step
1.
Enter system view.
2.
Enable the
authorization-fail-offline
feature.

Applying a NAS-ID profile to port security

By default, the device sends its device name in the NAS-Identifier attribute of all RADIUS requests.
A NAS-ID profile enables you to send different NAS-Identifier attribute strings in RADIUS requests
from different VLANs. The strings can be organization names, service names, or any user
categorization criteria, depending on the administrative requirements.
For example, map the NAS-ID companyA to all VLANs of company A. The device will send
companyA in the NAS-Identifier attribute for the RADIUS server to identify requests from any
Company A users.
You can apply a NAS-ID profile to port security globally or on a port. On a port, the device selects a
NAS-ID profile in the following order:
1.
The port-specific NAS-ID profile.
Command
system-view
port-security mac-move permit
Command
system-view
port-security authorization-fail
offline
201
Remarks
N/A
By default, MAC move is
disabled.
Remarks
N/A
By default, this feature is
disabled, and the device does not
log off users who fail ACL
authorization.

Advertisement

Table of Contents
loading

Table of Contents