HP 6125G HP 6125G & 6125G/XG Blade Switches Security Command Reference - Page 127

mac-authentication domain

Page 127 highlights

Use mac-authentication interface interface-list in system view to enable MAC authentication on a list of ports, or mac-authentication in interface view to enable MAC authentication on a port. Use undo mac-authentication in system view to disable MAC authentication globally. Use undo mac-authentication interface interface-list in system view to disable MAC authentication on a list of ports, or undo mac-authentication in interface view to disable MAC authentication on a port. By default, MAC authentication is not enabled globally or on any port. To use MAC authentication on a port, you must enable the function both globally and on the port. Examples # Enable MAC authentication globally. system-view [Sysname] mac-authentication Mac-auth is enabled globally. # Enable MAC authentication on port GigabitEthernet 1/0/1. system-view [Sysname] mac-authentication interface GigabitEthernet 1/0/1 Mac-auth is enabled on port GigabitEthernet1/0/1. Or system-view [Sysname] interface gigabitethernet 1/0/1 [Sysname-GigabitEthernet1/0/1] mac-authentication Mac-auth is enabled on port GigabitEthernet1/0/1. mac-authentication domain Syntax mac-authentication domain domain-name View undo mac-authentication domain System view, Ethernet interface view Default level 2: System level Parameters domain-name: Specifies an authentication domain name, a case-insensitive string of 1 to 24 characters. The domain name cannot contain any forward slash (/), colon (:), asterisk (*), question mark (?), less-than sign (), or at sign (@). Description Use mac-authentication domain to specify a global authentication domain in system view or a port specific authentication domain in interface view for MAC authentication users. Use undo mac-authentication domain to restore the default. By default, the default authentication domain is used for MAC authentication users. For more information about the default authentication domain, see the domain default enable command in "AAA configuration commands." 118

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291

118
Use
mac-authentication interface
interface-list
in system view to enable MAC authentication on a list of
ports, or
mac-authentication
in interface view to enable MAC authentication on a port.
Use
undo mac-authentication
in system view to disable MAC authentication globally.
Use
undo mac-authentication interface
interface-list
in system view to disable MAC authentication on a
list of ports, or
undo mac-authentication
in interface view to disable MAC authentication on a port.
By default, MAC authentication is not enabled globally or on any port.
To use MAC authentication on a port, you must enable the function both globally and on the port.
Examples
# Enable MAC authentication globally.
<Sysname> system-view
[Sysname] mac-authentication
Mac-auth is enabled globally.
# Enable MAC authentication on port GigabitEthernet 1/0/1.
<Sysname> system-view
[Sysname] mac-authentication interface GigabitEthernet 1/0/1
Mac-auth is enabled on port GigabitEthernet1/0/1.
Or
<Sysname> system-view
[Sysname] interface gigabitethernet 1/0/1
[Sysname-GigabitEthernet1/0/1] mac-authentication
Mac-auth is enabled on port GigabitEthernet1/0/1.
mac-authentication domain
Syntax
mac-authentication
domain
domain-name
undo mac-authentication
domain
View
System view, Ethernet interface view
Default level
2: System level
Parameters
domain-name
: Specifies an authentication domain name, a case-insensitive string of 1 to 24 characters.
The domain name cannot contain any forward slash (/), colon (:), asterisk (*), question mark (?),
less-than sign (<), greater-than sign (>), or at sign (@).
Description
Use
mac-authentication domain
to specify a global authentication domain in system view or a port
specific authentication domain in interface view for MAC authentication users.
Use
undo mac-authentication domain
to restore the default.
By default, the default authentication domain is used for MAC authentication users. For more information
about the default authentication domain, see the
domain default
enable
command in "
AAA
configuration commands
."