Applying A Nas-Id Profile To Port Security; Displaying And Maintaining Port Security - HP FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Applying a NAS-ID profile to port security

By default, the device sends its device name in the NAS-Identifier attribute of all RADIUS requests.
A NAS-ID profile enables you to send different NAS-Identifier attribute strings in RADIUS requests
from different VLANs. The strings can be organization names, service names, or any user
categorization criteria, depending on the administrative requirements.
For example, map the NAS-ID companyA to all VLANs of company A. The device will send
companyA in the NAS-Identifier attribute for the RADIUS server to identify requests from any
Company A users.
You can apply a NAS-ID profile to port security globally or on a port. On a port, the device selects a
NAS-ID profile in the following order:
1.
The port-specific NAS-ID profile.
2.
The NAS-ID profile applied globally.
If no NAS-ID profile is applied or no matching binding is found in the selected profile, the device uses
the device name as the NAS-ID.
For more information about the NAS-ID profile configuration, see
To apply a NAS-ID profile to port security:
Step
1.
Enter system view.
2.
Apply a NAS-ID profile to
port security.

Displaying and maintaining port security

Execute display commands in any view:
Task
Display the port security configuration,
operation information, and statistics.
Display information about secure MAC
addresses.
Display information about blocked MAC
addresses.
Command
system-view
In system view:
port-security nas-id-profile
profile-name
In Layer 2 Ethernet interface
view:
a. interface interface-type
interface-number
b. port-security
nas-id-profile
profile-name
Command
display port-security [ interface interface-type
interface-number ]
display port-security mac-address security [ interface
interface-type interface-number ] [ vlan vlan-id ] [ count ]
display port-security mac-address block [ interface
interface-type interface-number ] [ vlan vlan-id ] [ count ]
202
"Configuring
AAA."
Remarks
N/A
By default, no NAS-ID profile is
applied in system view or in Layer
2 Ethernet interface view.

Advertisement

Table of Contents
loading

Table of Contents