Mac-Authentication Max-User - H3C MSR Series Command Reference Manual

Comware 7 security
Hide thumbs Also See for MSR Series:
Table of Contents

Advertisement

Syntax
mac-authentication host-mode multi-vlan
undo mac-authentication host-mode
Default
MAC authentication multi-VLAN mode is disabled on a port. When the port receives a packet
sourced from an authenticated MAC address in a VLAN not matching the existing MAC-VLAN
mapping, the device logs off and reauthenticates the user.
Views
Ethernet interface view
Predefined user roles
network-admin
Usage guidelines
The MAC authentication multi-VLAN mode prevents an authenticated online user from service
interruption caused by VLAN changes on a port. When the port receives a packet sourced from the
user in a VLAN not matching the existing MAC-VLAN mapping, the device neither logs off the user
nor reauthenticates the user. The device creates a new MAC-VLAN mapping for the user, and traffic
transmission is not interrupted. The original MAC-VLAN mapping for the user remains on the device
until it dynamically ages out. As a best practice, configure this feature on hybrid or trunk ports.
This feature improves transmission of data that is vulnerable to delay and interference. It is typically
applicable to IP phone users.
Examples
# Enable MAC authentication multi-VLAN mode on GigabitEthernet 1/0/1.
<Sysname> system-view
[Sysname] interface gigabitethernet 1/0/1
[Sysname-GigabitEthernet1/0/1] mac-authentication host-mode multi-vlan
Related commands
display mac-authentication

mac-authentication max-user

Use mac-authentication max-user to set the maximum number of concurrent MAC authentication
users on a port.
Use undo mac-authentication max-user to restore the default.
Syntax
mac-authentication max-user max-number
undo mac-authentication max-user
Default
The device allows a maximum of 4294967295 concurrent MAC authentication users on a port.
Views
Ethernet interface view
Predefined user roles
network-admin
199

Advertisement

Table of Contents
loading

Table of Contents