Configuring Mac Authentication Delay; Enabling Parallel Processing Of Mac Authentication And 802.1X Authentication - HPE FlexNetwork 5510 HI Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 5510 HI Series:
Table of Contents

Advertisement

This feature improves transmission of data that is vulnerable to delay and interference. It is typically
applicable to IP phone users.
To enable MAC authentication multi-VLAN mode on a port:
Step
1.
Enter system view.
2.
Enter
interface view.
3.
Enable MAC authentication
multi-VLAN mode.

Configuring MAC authentication delay

When both 802.1X authentication and MAC authentication are enabled on a port, you can delay
MAC authentication so that 802.1X authentication is preferentially triggered.
If no 802.1X authentication is triggered or 802.1X authentication fails within the delay period, the port
continues to process MAC authentication.
Do
not
mac-else-userlogin-secure-ext when you use MAC authentication delay. The delay does not take
effect on a port in either of the two modes. For more information about port security modes, see
"Configuring port
To configure MAC authentication delay:
Step
1.
Enter system view.
2.
Enter
interface view.
3.
Enable MAC authentication
delay and set the delay
timer.
Enabling parallel processing of MAC
authentication and 802.1X authentication
IMPORTANT:
This feature is available in Release 1121 and later.
This feature enables a port that processes MAC authentication after 802.1X authentication is
finished to process MAC authentication in parallel with 802.1X authentication.
When the port receives a packet from an unknown MAC address, it sends a unicast
EAP-Request/Identity packet to the MAC address. After that, the port immediately processes MAC
authentication without waiting for the 802.1X authentication result.
Command
system-view
Layer
2
Ethernet
interface
interface-number
mac-authentication host-mode
multi-vlan
set
the
port
security."
Command
system-view
Layer
2
Ethernet
interface
interface-number
mac-authentication
auth-delay time
interface-type
security
mode
to
interface-type
110
Remarks
N/A
N/A
By default, this feature is disabled
on a port. When the port receives
a
packet
sourced
authenticated user in a VLAN not
matching the existing MAC-VLAN
mapping, the device logs off and
reauthenticates the user.
mac-else-userlogin-secure
Remarks
N/A
N/A
timer
By default, MAC authentication
delay is disabled.
from
an
or

Hide quick links:

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the FlexNetwork 5510 HI Series and is the answer not in the manual?

Table of Contents

Save PDF