HP 6125G HP 6125G & 6125G/XG Blade Switches Security Configuration Gui - Page 116

Specifying a MAC authentication domain, Displaying and maintaining MAC authentication

Page 116 highlights

Step 2. Enable MAC authentication. 3. Set the maximum number of concurrent MAC authentication users allowed on a port. Command • (Approach 1) In system view: mac-authentication interface interface-list • (Approach 2) In interface view: a. interface interface-type interface-number b. mac-authentication mac-authentication max-user user-number Remarks Disabled by default. Enable MAC authentication for ports in bulk in system view or an individual port in Ethernet interface view. Optional. By default, the maximum number of concurrent MAC authentication users is 2048. NOTE: You cannot add a MAC authentication enabled port in to a link aggregation group or service loopback group, or enable MAC authentication on a port already in a link aggregation group or service loopback group. Specifying a MAC authentication domain By default, MAC authentication users are in the system default authentication domain. To implement different access policies for users, you can specify authentication domains for MAC authentication users in the following ways: • Specify a global authentication domain in system view. This domain setting applies to all ports. • Specify an authentication domain for an individual port in Ethernet interface view. MAC authentication chooses an authentication domain for users on a port in this order: the interface-specific domain, the global domain, and the default domain. For more information about authentication domains, see "Configuring AAA." To specify an authentication domain for MAC authentication users: Step Command 1. Enter system view. system-view • (Approach 1) In system view: mac-authentication domain domain-name 2. Specify an authentication domain for MAC • (Approach 2) In interface view: authentication users. a. interface interface-type interface-number b. mac-authentication domain domain-name Remarks N/A Use either approach. By default, the system default authentication domain is used for MAC authentication users. Displaying and maintaining MAC authentication 106

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285

106
Step
Command
Remarks
2.
Enable MAC authentication.
(Approach 1) In system view:
mac-authentication
interface
interface-list
(Approach 2) In interface
view:
a.
interface
interface-type
interface-number
b.
mac-authentication
Disabled by default.
Enable MAC authentication for
ports in bulk in system view or an
individual port in Ethernet
interface view.
3.
Set the maximum number of
concurrent MAC authentication
users allowed on a port.
mac-authentication max-user
user-number
Optional.
By default, the maximum number
of concurrent MAC
authentication users is 2048.
NOTE:
You cannot add a MAC authentication enabled port in to a link aggregation group or service loopback
group, or enable MAC authentication on a port already in a link aggregation group or service loopback
group.
Specifying a MAC authentication domain
By default, MAC authentication users are in the system default authentication domain. To implement
different access policies for users, you can specify authentication domains for MAC authentication users
in the following ways:
Specify a global authentication domain in system view. This domain setting applies to all ports.
Specify an authentication domain for an individual port in Ethernet interface view.
MAC authentication chooses an authentication domain for users on a port in this order: the
interface-specific domain, the global domain, and the default domain. For more information about
authentication domains, see "
Configuring AAA.
"
To specify an authentication domain for MAC authentication users:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Specify an authentication
domain for MAC
authentication users.
(Approach 1) In system view:
mac-authentication domain
domain-name
(Approach 2) In interface view:
a.
interface
interface-type
interface-number
b.
mac-authentication domain
domain-name
Use either approach.
By default, the system default
authentication domain is used for
MAC authentication users.
Displaying and maintaining MAC authentication