HP 6125G HP 6125G & 6125G/XG Blade Switches Security Configuration Gui - Page 115

Basic configuration for MAC authentication, Configuring MAC authentication globally, Configuring MAC

Page 115 highlights

Task Specifying a MAC authentication domain Remarks Optional Basic configuration for MAC authentication • Create and configure an authentication domain, also called "an ISP domain." • For local authentication, create local user accounts, and specify the lan-access service for the accounts. • For RADIUS authentication, check that the device and the RADIUS server can reach each other, and create user accounts on the RADIUS server. If you are using MAC-based accounts, make sure that the username and password for each account is the same as the MAC address of the MAC authentication users. MAC authentication can take effect on a port only when it is enabled globally and on the port. Configuring MAC authentication globally Step 1. Enter system view. 2. Enable MAC authentication globally. Command system-view mac-authentication Remarks N/A Disabled by default. 3. Configure MAC authentication timers. mac-authentication timer { offline-detect offline-detect-value | quiet quiet-value | server-timeout server-timeout-value } Optional. By default, the offline detect timer is 300 seconds, the quiet timer is 60 seconds, and the server timeout timer is 100 seconds. mac-authentication user-name-format 4. Configure the properties of MAC authentication user accounts. { fixed [ account name ] [ password { cipher | simple } password ] | mac-address [ { with-hyphen | without-hyphen } [ lowercase | uppercase ] ] } Optional. By default, the username and password for a MAC authentication user account must be a MAC address in lower case without hyphens. NOTE: When global MAC authentication is enabled, the EAD fast deployment function cannot take effect. Configuring MAC authentication on a port Step 1. Enter system view. Command system-view Remarks N/A 105

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285

105
Task
Remarks
Specifying a MAC authentication domain
Optional
Basic configuration for MAC authentication
Create and configure an authentication domain, also called "an ISP domain."
For local authentication, create local user accounts, and specify the
lan-access
service for the
accounts.
For RADIUS authentication, check that the device and the RADIUS server can reach each other, and
create user accounts on the RADIUS server.
If you are using MAC-based accounts, make sure that the username and password for each account is
the same as the MAC address of the MAC authentication users.
MAC authentication can take effect on a port only when it is enabled globally and on the port.
Configuring MAC authentication globally
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enable MAC
authentication globally.
mac-authentication
Disabled by default.
3.
Configure MAC
authentication timers.
mac-authentication
timer
{
offline-detect
offline-detect-value
|
quiet
quiet-value
|
server-timeout
server-timeout-value
}
Optional.
By default, the offline detect timer is
300 seconds, the quiet timer is 60
seconds, and the server timeout
timer is 100 seconds.
4.
Configure the properties
of MAC authentication
user accounts.
mac-authentication user-name-format
{
fixed
[
account
name
] [
password
{
cipher
|
simple
}
password
]
|
mac-address
[ {
with-hyphen
|
without-hyphen
} [
lowercase
|
uppercase
] ] }
Optional.
By default, the username and
password for a MAC
authentication user account must
be a MAC address in lower case
without hyphens.
NOTE:
When global MAC authentication is enabled, the EAD fast deployment function cannot take effect.
Configuring MAC authentication on a port
Step
Command
Remarks
1.
Enter system view.
system-view
N/A