Acl Assigning; Configuring Mac Authentication; Configuration Prerequisites; Configuration Procedure - 3Com 4500G Family Configuration Manual

24/48 port
Hide thumbs Also See for 4500G Family:
Table of Contents

Advertisement

MAC authentication supports MAC-based guest VLAN (MGV). With MGV configured on a port, users
failing the authentication on the port are authorized to access the resources in the guest VLAN.
If a user in the guest VLAN initiates another authentication process but fails the authentication, the
device will keep the user in the guest VLAN. If the user passes the authentication, the device will add
the user to the assigned VLAN or return the user to its original VLAN, depending on whether the
authentication server assigns a VLAN.

ACL Assigning

ACLs assigned by an authorization server are referred to as authorization ACLs, which are designed to
control access to network resources. If the RADIUS server is configured with authorization ACLs, the
device will permit or deny data flows traversing through the port through which a user accesses the
device according to the authorization ACLs. You can change access rights of users by modifying
authorization ACL settings on the RADIUS server.

Configuring MAC Authentication

Configuration Prerequisites

Create and configure an ISP domain.
For local authentication, create the local users and configure the passwords.
For RADIUS authentication, ensure that a route is available between the device and the RADIUS
server, and add the usernames and passwords on the server.
When adding usernames and passwords on the device or server, ensure that:
The type of username and password must be consistent with that used for MAC authentication.
All the letters in the MAC address to be used as the username and password must be in lower
case.
The service type of the local users must be configured as lan-access.

Configuration Procedure

Follow these steps to configure MAC authentication:
To do...
Enter system view
Enable MAC authentication
globally
Enable MAC authentication
for specified ports
Specify the ISP domain for
Use the command...
system-view
mac-authentication
mac-authentication interface
interface-list
interface interface-type
interface-number
mac-authentication
quit
mac-authentication domain isp-name
1-3
Remarks
Required
Disabled by default
Required
Use either approach.
Disabled by default
Optional

Hide quick links:

Advertisement

Chapters

Table of Contents
loading

Table of Contents