Configuration Procedure; Configuring The Keep-Online Feature; Including User Ip Addresses In Mac Authentication Requests - HPE Moonshot 45Gc Security Configuration Manual

Switch module
Table of Contents

Advertisement

Configuration procedure

To enable the MAC authentication critical voice VLAN feature on a port:
Step
1.
Enter system view.
2.
Enter Layer 2 Ethernet
interface view.
3.
Enable the MAC
authentication critical voice
VLAN feature on a port.

Configuring the keep-online feature

By default, the device logs off online MAC authentication users if no server is reachable for MAC
reauthentication. The keep-online feature keeps authenticated MAC authentication users online
when no server is reachable for MAC reauthentication.
In a fast-recovery network, you can use the keep-online feature to prevent MAC authentication users
from coming online and going offline frequently.
To configure the keep-online feature:
Step
1.
Enter system view.
2.
Enter Layer 2 Ethernet
interface view.
3.
Enable the keep-online feature
for authenticated MAC
authentication users on the
port.
Including user IP addresses in MAC
authentication requests
This feature enables the device to add user IP addresses to the MAC authentication requests that
are sent to an IMC server.
Upon receiving an authentication request, the IMC server compares the user IP and MAC addresses
in the request with its local IP-MAC mapping of the user. If a match is found, the IMC server verifies
the user valid. If no match is found, the user fails the MAC authentication. For information about IMC
user IP-MAC bindings, see HPE IMC User Access Manager Administrator Guide.
When you configure this feature, follow these guidelines and restrictions:
This feature takes effect only on MAC authentication users who use static IP addresses. Users
who obtain IP addresses through DHCP are not affected.
Command
system-view
interface interface-type
interface-number
mac-authentication critical-voice
vlan
Command
system-view
interface interface-type
interface-number
mac-authentication
re-authenticate
server-unreachable keep-online
114
Remarks
N/A
N/A
By default, the MAC
authentication critical voice VLAN
feature is disabled on the port.
Remarks
N/A
N/A
By default, the keep-online
feature is disabled.
This command takes effect only
when the authentication server
assigns reauthentication
attributes to the device.

Advertisement

Table of Contents
loading

Table of Contents