Enabling Parallel Processing Of Mac Authentication And 802.1X Authentication; Configuration Restrictions And Guidelines; Configuration Procedure - HPE Moonshot 45Gc Security Configuration Manual

Switch module
Table of Contents

Advertisement

Enabling parallel processing of MAC
authentication and 802.1X authentication
This feature enables a port that processes MAC authentication after 802.1X authentication is
finished to process MAC authentication in parallel with 802.1X authentication.
When the port receives a packet from an unknown MAC address, it sends a unicast
EAP-Request/Identity packet to the MAC address. After that, the port immediately processes MAC
authentication without waiting for the 802.1X authentication result.
After MAC authentication succeeds, the port is assigned to the MAC authentication authorization
VLAN.
If 802.1X authentication fails, the MAC authentication result takes effect.
If 802.1X authentication succeeds, the device handles the port and the MAC address based on
the 802.1X authentication result.

Configuration restrictions and guidelines

When you enable parallel processing of MAC authentication and 802.1X authentication on a port,
follow these restrictions and guidelines:
Make sure the port meets the following requirements:
The port is configured with both 802.1X authentication and MAC authentication and
performs MAC-based access control for 802.1X authentication.
The port is enabled with the 802.1X unicast trigger.
For the port to perform MAC authentication before it is assigned to the 802.1X guest VLAN,
delay assigning the port to the 802.1X guest VLAN.
For information about 802.1X guest VLAN assignment delay, see "Configuring 802.1X."
For the parallel processing feature to work correctly, do not enable MAC authentication delay on
the port. This operation will delay MAC authentication after 802.1X authentication is triggered.
To configure both 802.1X authentication and MAC authentication on the port, use one of the
following methods:
Enable the 802.1X and MAC authentication features separately on the port.
Enable port security on the port. The port security mode must be userlogin-secure-or-mac
or userlogin-secure-or-mac-ext.
For information about port security mode configuration, see "Configuring port security."

Configuration procedure

To enable parallel processing of MAC authentication and 802.1X authentication on a port:
Step
1.
Enter system view.
2.
Enter Layer 2 Ethernet
interface view.
3.
Enable parallel
processing of MAC
authentication and
802.1X authentication on
the port.
Command
system-view
interface interface-type
interface-number
mac-authentication
parallel-with-dot1x
111
Remarks
N/A
N/A
By default, this feature is disabled.

Advertisement

Table of Contents
loading

Table of Contents