For information about the dot1x guest-vlan-delay new-mac command, see "802.1X
commands."
•
Do not enable MAC authentication delay on the port. This operation will delay MAC
authentication after 802.1X authentication is triggered.
•
To configure both 802.1X authentication and MAC authentication on the port, use one of the
following methods:
Enable the 802.1X and MAC authentication features separately on the port.
Enable port security on the port. The port security mode must be userlogin-secure-or-mac
or userlogin-secure-or-mac-ext.
For information about port security mode configuration, see port security in Security
Configuration Guide.
Examples
#
Enable
Ten-GigabitEthernet 1/0/1.
<Sysname> system-view
[Sysname] interface ten-gigabitethernet 1/0/1
[Sysname-Ten-GigabitEthernet1/0/1] mac-authentication parallel-with-dot1x
Related commands
display mac-authentication
mac-authentication re-authenticate server-unreachable
keep-online
Use mac-authentication re-authenticate server-unreachable keep-online to enable the
keep-online feature on a port.
Use undo mac-authentication re-authenticate server-unreachable to restore the default.
Syntax
mac-authentication re-authenticate server-unreachable keep-online
undo mac-authentication re-authenticate server-unreachable
Default
The keep-online feature is disabled on a port. The device logs off online MAC authentication users if
no server is reachable for MAC reauthentication.
Views
Ethernet interface view
Predefined user roles
network-admin
Usage guidelines
The keep-online feature keeps authenticated MAC authentication users online when no server is
reachable for MAC reauthentication.
This command takes effect only after the server assigns the Radius-request action attribute to the
authenticated MAC authentication user (see
device will reauthenticate the user when the session timeout timer expires.
parallel
processing
of
MAC
authentication
"display mac-authentication
12
and
802.1X
authentication
connection"). The access
on