HP 6125G HP 6125G & 6125G/XG Blade Switches Security Command Reference - Page 147

Keyword, Security mode, Description, port-security port-mode, port-security max-mac-count

Page 147 highlights

Keyword Security mode Description userlogin userLogin In this mode, a port performs 802.1X authentication and implements port-based access control. If one 802.1X user passes authentication, all the other 802.1X users of the port can access the network without authentication. userlogin-secure userLoginSecure In this mode, a port performs 802.1X authentication and implements MAC-based access control. It services only one user passing 802.1X authentication. userlogin-secure-e userLoginSecureEx Similar to the userLoginSecure mode except that this mode xt t supports multiple online 802.1X users. userlogin-secure-or -mac macAddressOrUse rLoginSecure This mode is the combination of the userLoginSecure and macAddressWithRadius modes. For wired users, the port performs MAC authentication 30 seconds after receiving non-802.1X frames and performs 802.1X authentication upon receiving 802.1X frames. userlogin-secure-or -mac-ext macAddressOrUse rLoginSecureExt Similar to the macAddressOrUserLoginSecure mode except that a port in this mode supports multiple 802.1X and MAC authentication users. userlogin-withoui userLoginWithOUI Similar to the userLoginSecure mode. In addition, a port in this mode also permits frames from a user whose MAC address contains a specific OUI (organizationally unique identifier). For wired users, the port performs 802.1X authentication upon receiving 802.1X frames, and performs OUI check upon receiving non-802.1X frames. Description Use port-security port-mode to set the port security mode of a port. Use undo port-security port-mode to restore the default. By default, a port operates in noRestrictions mode, where port security does not take effect. To change the security mode of a port security enabled port, you must set the port in noRestrictions mode first. When the port has online users, you cannot change port security mode. IMPORTANT: If you are configuring the autoLearn mode, first set port security's limit on the number of MAC addresses by using the port-security max-mac-count command. You cannot change the setting when the port is operating in autoLearn mode. When port security is enabled, you cannot manually enable 802.1X or MAC authentication, or change the access control mode or port authorization state. The port security automatically modifies these settings in different security modes. Related commands: display port-security. Examples # Enable port security and set port GigabitEthernet 1/0/1 in secure mode. system-view [Sysname] port-security enable [Sysname] interface gigabitethernet 1/0/1 138

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291

138
Keyword
Security mode
Description
userlogin
userLogin
In this mode, a port performs 802.1X authentication and
implements port-based access control.
If one 802.1X user passes authentication, all the other 802.1X
users of the port can access the network without authentication.
userlogin-secure
userLoginSecure
In this mode, a port performs 802.1X authentication and
implements MAC-based access control. It services only one user
passing 802.1X authentication.
userlogin-secure-e
xt
userLoginSecureEx
t
Similar to the userLoginSecure mode except that this mode
supports multiple online 802.1X users.
userlogin-secure-or
-mac
macAddressOrUse
rLoginSecure
This mode is the combination of the userLoginSecure and
macAddressWithRadius modes.
For wired users, the port performs MAC authentication 30 seconds
after receiving non-802.1X frames and performs 802.1X
authentication upon receiving 802.1X frames.
userlogin-secure-or
-mac-ext
macAddressOrUse
rLoginSecureExt
Similar to the macAddressOrUserLoginSecure mode except that a
port in this mode supports multiple 802.1X and MAC
authentication users.
userlogin-withoui
userLoginWithOUI
Similar to the userLoginSecure mode. In addition, a port in this
mode also permits frames from a user whose MAC address
contains a specific OUI (organizationally unique identifier).
For wired users, the port performs 802.1X authentication upon
receiving 802.1X frames, and performs OUI check upon receiving
non-802.1X frames.
Description
Use
port-security port-mode
to set the port security mode of a port.
Use
undo port-security port-mode
to restore the default.
By default, a port operates in noRestrictions mode, where port security does not take effect.
To change the security mode of a port security enabled port, you must set the port in noRestrictions mode
first. When the port has online users, you cannot change port security mode.
IMPORTANT:
If you are configuring the autoLearn mode, first set port security's limit on the number of MAC addresses
by using the
port-security max-mac-count
command. You cannot change the setting when the port is
operating in autoLearn mode.
When port security is enabled, you cannot manually enable 802.1X or MAC authentication, or change
the access control mode or port authorization state. The port security automatically modifies these
settings in different security modes.
Related commands:
display port-security
.
Examples
# Enable port security and set port GigabitEthernet 1/0/1 in secure mode.
<Sysname> system-view
[Sysname] port-security enable
[Sysname] interface gigabitethernet 1/0/1