HP 6125G HP 6125G & 6125G/XG Blade Switches Security Command Reference - Page 130

MAC authentication supports the following types of user account

Page 130 highlights

Default level 2: System level Parameters fixed: Uses a shared account for all MAC authentication users. account name: Specifies the username for the shared account. The name takes a case-insensitive string of 1 to 55 characters. If no username is specified, the default name mac applies. password: Specifies the password for the shared user account. cipher: Sets a ciphertext password. simple: Sets a plaintext password. password: Specifies the password. This argument is case sensitive. If simple is specified, the password must be a string of 1 to 63 characters. If cipher is specified, the password must be a ciphertext string of 1 to 117 characters. mac-address: Uses MAC-based user accounts for MAC authentication users. If this option is specified, you must create one user account for each user, and use the MAC address of the user as both the username and password for the account. You can also specify the format of username and password: • with-hyphen-Hyphenates the MAC address, for example xx-xx-xx-xx-xx-xx. • without-hyphen-Excludes hyphens from the MAC address, for example, xxxxxxxxxxxx. • lowercase-Enters letters in lower case. • uppercase-Capitalizes letters. Description Use mac-authentication user-name-format to configure the type of user accounts for MAC authentication users. Use undo mac-authentication user-name-format to restore the default. By default, each user's MAC address is used as the username and password for MAC authentication, and letters must be input in lower case without hyphens. MAC authentication supports the following types of user account: • One MAC-based user account for each user. A user can pass MAC authentication only when its MAC address matches a MAC-based user account. This approach is suitable for an insecure environment. • One shared user account for all users. Any user can pass MAC authentication on any MAC authentication enabled port. You can use this approach in a secure environment to limit network resources accessible to MAC authentication users, for example, by assigning an authorized ACL or VLAN for the shared account. The configuration file saves the password for a shared user account in cipher text, regardless of whether it is specified in cipher text or plain text. Related commands: display mac-authentication. Examples # Configure a shared account for MAC authentication users: set the username as abc and password as xyz in plain text. system-view [Sysname] mac-authentication user-name-format fixed account abc password simple xyz 121

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291

121
Default level
2: System level
Parameters
fixed
: Uses a shared account for all MAC authentication users.
account
name
: Specifies the username for the shared account. The name
takes a case-insensitive string
of 1 to 55 characters. If no username is specified, the default name
mac
applies.
password
: Specifies the password for the shared user account.
cipher
: Sets a ciphertext password.
simple
: Sets a plaintext password.
password
: Specifies the password. This argument is case sensitive. If
simple
is specified, the password
must be a string of 1 to 63 characters. If
cipher
is specified, the password must be a ciphertext string of
1 to 117 characters.
mac-address
: Uses MAC-based user accounts for MAC authentication users. If this option is specified,
you must create one user account for each user, and use the MAC address of the user as both the
username and password for the account. You can also specify the format of username and password:
with-hyphen
—Hyphenates the MAC address, for example xx-xx-xx-xx-xx-xx.
without-hyphen
—Excludes hyphens from the MAC address, for example, xxxxxxxxxxxx.
lowercase
—Enters letters in lower case.
uppercase
—Capitalizes letters.
Description
Use
mac-authentication user-name-format
to configure the type of user accounts for MAC authentication
users.
Use
undo mac-authentication user-name-format
to restore the default.
By default, each user's MAC address is used as the username and password for MAC authentication,
and letters must be input in lower case without hyphens.
MAC authentication supports the following types of user account:
One MAC-based user account for each user. A user can pass MAC authentication only when its
MAC address matches a MAC-based user account. This approach is suitable for an insecure
environment.
One shared user account for all users. Any user can pass MAC authentication on any MAC
authentication enabled port. You can use this approach in a secure environment to limit network
resources accessible to MAC authentication users, for example, by assigning an authorized ACL or
VLAN for the shared account.
The configuration file saves the password for a shared user account in cipher text, regardless of whether
it is specified in cipher text or plain text.
Related commands:
display mac-authentication
.
Examples
# Configure a shared account for MAC authentication users: set the username as
abc
and password as
xyz
in plain text.
<Sysname> system-view
[Sysname] mac-authentication user-name-format fixed account abc password simple xyz