Ignoring Authorization Information From The Server; Enabling Mac Move - HPE FlexNetwork 5510 HI Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 5510 HI Series:
Table of Contents

Advertisement

Step
1.
Enter system view.
2.
(Optional.)
secure
timer.
3.
Configure
MAC address.
4.
Enter Layer 2 Ethernet
interface view.
5.
(Optional.)
inactivity aging.
6.
(Optional.) Enable the
dynamic secure MAC
feature.

Ignoring authorization information from the server

You can configure a port to ignore the authorization information received from the server (local or
remote) after an 802.1X or MAC authentication user passes authentication.
To configure a port to ignore authorization information from the server:
Step
1.
Enter system view.
2.
Enter
interface view.
3.
Ignore
information received from the
authentication server.

Enabling MAC move

MAC move allows 802.1X or MAC authenticated users to move between ports on a device. For
example, if an authenticated 802.1X user moves to another 802.1X-enabled port on the device, the
authentication session is deleted from the first port. The user is reauthenticated on the new port.
If MAC move is disabled and an 802.1X authenticated user moves to another port, the user is not
reauthenticated.
Command
system-view
Set
the
port-security timer autolearn aging
MAC
aging
time-value
In
port-security
security [ sticky ] mac-address
interface
interface-number vlan vlan-id
In Layer 2 Ethernet interface view:
a
secure
a. interface
b. port-security
c. quit
interface
interface-number
Enable
port-security
aging-type inactivity
port-security mac-address dynamic
Command
system-view
Layer
2
Ethernet
interface
interface-number
the
authorization
port-security
ignore
system
mac-address
interface-type
interface-type
interface-number
mac-address
security [ sticky ] mac-address
vlan vlan-id
interface-type
mac-address
interface-type
authorization
193
Remarks
N/A
By
default,
addresses do not age out.
view:
By default,
no secure
address exists.
In the same VLAN, a MAC
address cannot be specified as
both a static secure MAC address
and a sticky MAC address.
N/A
By default, the inactivity aging
feature is disabled.
By default, the dynamic secure
MAC feature is disabled. Sticky
MAC addresses can be saved to
the configuration file. Once saved,
they can survive a device reboot.
Remarks
N/A
N/A
By default, a port uses the
authorization information received
from the authentication server.
secure
MAC
MAC

Hide quick links:

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the FlexNetwork 5510 HI Series and is the answer not in the manual?

Subscribe to Our Youtube Channel

Table of Contents

Save PDF