Configuring Mac Authentication Delay; Configuring A Mac Authentication Guest Vlan; Configuration Prerequisites - HP FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

nor reauthenticates the user. The device creates a new MAC-VLAN mapping for the user, and traffic
transmission is not interrupted. The original MAC-VLAN mapping for the user remains on the device
until it dynamically ages out. As a best practice, configure this feature on hybrid or trunk ports.
This feature improves transmission of data that is vulnerable to delay and interference. It is typically
applicable to IP phone users.
To enable MAC authentication multi-VLAN mode on a port:
Step
1.
Enter system view.
2.
Enter Layer 2 Ethernet
interface view.
3.
Enable MAC authentication
multi-VLAN mode.

Configuring MAC authentication delay

When both 802.1X authentication and MAC authentication are enabled on a port, you can delay
MAC authentication so that 802.1X authentication is preferentially triggered.
If no 802.1X authentication is triggered or 802.1X authentication fails within the delay period, the port
continues to process MAC authentication.
Do
not
mac-else-userlogin-secure-ext when you use MAC authentication delay. The delay does not take
effect on a port in either of the two modes. For more information about port security modes, see
"Configuring port
To configure MAC authentication delay:
Step
1.
Enter system view.
2.
Enter Layer 2 Ethernet
interface view.
3.
Enable MAC authentication
delay and set the delay
timer.

Configuring a MAC authentication guest VLAN

Configuration prerequisites

You must configure the MAC authentication guest VLAN on a hybrid port. Before you configure the
MAC authentication guest VLAN on a hybrid port, complete the following tasks:
Enable MAC authentication globally and on the port.
Enable MAC-based VLAN on the port.
Command
system-view
interface interface-type
interface-number
mac-authentication host-mode
multi-vlan
set
the
port
security."
Command
system-view
interface interface-type
interface-number
mac-authentication timer
auth-delay time
security
mode
121
Remarks
N/A
N/A
By default, this feature is disabled
on a port. When the port receives
a packet sourced from an
authenticated user in a VLAN not
matching the existing MAC-VLAN
mapping, the device logs off and
reauthenticates the user.
to
mac-else-userlogin-secure
Remarks
N/A
N/A
By default, MAC authentication
delay is disabled.
or

Advertisement

Table of Contents
loading

Table of Contents