HP A5830 Series Configuration Manual page 116

Security switch
Hide thumbs Also See for A5830 Series:
Table of Contents

Advertisement

Authentication—Security modes in this category implement MAC authentication, 802.1X
authentication, or a combination of these two authentication methods.
Table 9
describes the port security modes and the security features.
Table 9 Port security modes
Purpose
Turning off the port security
feature
Controlling MAC address
learning
Performing 802.1X
authentication
Performing MAC authentication
Performing a combination of
MAC authentication and
802.1X authentication
userLogin—Specifies 802.1X authentication and port-based access control.
macAddress—Specifies MAC authentication.
Else—Specifies that the authentication method before Else is applied first. If the authentication fails,
whether to turn to the authentication method following Else depends on the protocol type of the
authentication request.
Or—Typically, in a security mode with Or, the authentication method to be used depends on the
protocol type of the authentication request.
userLogin with Secure—Specifies 802.1X authentication and MAC-based access control.
Ext—Indicates allowing multiple 802.1X users to be authenticated and serviced at the same time. A
security mode without Ext allows only one user to pass 802.1X authentication.
Controlling MAC address learning
autoLearn
A port in this mode can learn MAC addresses and allow frames from learned or configured MAC
addresses to pass. The automatically learned MAC addresses are secure MAC addresses. You can also
configure secure MAC addresses by using the port-security mac-address security command. A secure
MAC address never ages out by default.
When the number of secure MAC addresses reaches the upper limit, the port transitions to secure mode.
Security mode
noRestrictions (the default mode)
In this mode, port security is disabled on the port,
and access to the port is not restricted.
autoLearn
secure
userLogin
userLoginSecure
userLoginSecureExt
userLoginWithOUI
macAddressWithRadius
macAddressOrUserLoginSecure
Or
macAddressOrUserLoginSecureExt
macAddressElseUserLoginSecure
Else
macAddressElseUserLoginSecureExt
108
Features that can
be triggered
NTK/intrusion
protection
NTK/intrusion
protection
NTK/intrusion
protection
NTK/intrusion
protection

Advertisement

Table of Contents
loading

Table of Contents