Configuring A Mac Authentication Critical Vlan - HPE FlexNetwork 5510 HI Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 5510 HI Series:
Table of Contents

Advertisement

When you configure the MAC authentication guest VLAN on a port, follow the guidelines in
Table 12 Relationships of the MAC authentication guest VLAN with other security features
Feature
Quiet feature of MAC
authentication
Super VLAN
Port intrusion protection
To configure the MAC authentication guest VLAN on a port:
Step
1.
Enter system view.
2.
Enter Layer 2 Ethernet
interface view.
3.
Specify
authentication
VLAN on the port.
4.
(Optional.)
authentication
for users in the MAC
authentication
VLAN.

Configuring a MAC authentication critical VLAN

You must configure the MAC authentication critical VLAN on a hybrid port. Before you configure the
MAC authentication critical VLAN on a hybrid port, complete the following tasks:
Enable MAC authentication globally and on the port.
Enable MAC-based VLAN on the port.
Create the VLAN to be specified as the MAC authentication critical VLAN.
Configure the VLAN as an untagged member on the port.
When you configure the MAC authentication critical VLAN on a port, follow the guidelines in
13.
Relationship description
The MAC authentication guest VLAN feature
has higher priority.
When a user fails MAC authentication, the
user can access the resources in the guest
VLAN. The user's MAC address is not marked
as a silent MAC address.
You cannot specify a VLAN as both a super
VLAN and a MAC authentication guest VLAN.
The guest VLAN feature has higher priority
than the block MAC action but lower priority
than the shutdown port action of the port
intrusion protection feature.
Command
system-view
interface
interface-number
the
MAC
mac-authentication
guest
guest-vlan guest-vlan-id
Set
the
interval
mac-authentication
guest-vlan
guest
period-value
Remarks
N/A
interface-type
N/A
By default, no MAC authentication guest
VLAN is specified on a port.
You can configure only one MAC
authentication guest VLAN on a port.
The default setting is 30 seconds.
auth-period
This command is available in Release
1121 and later.
112
Table
Reference
See
"Configuring
authentication
timers."
See Layer 2—LAN Switching
Configuration Guide.
See
"Configuring
security."
12.
MAC
port
Table

Hide quick links:

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the FlexNetwork 5510 HI Series and is the answer not in the manual?

Table of Contents

Save PDF