HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 88

Configuration prerequisites, Configuration task list, Enabling MAC authentication

Page 88 highlights

For more information about configuring local authentication and RADIUS authentication, see "Configuring AAA." Configuration prerequisites Before you configure MAC authentication, complete the following tasks: 1. Configure an ISP domain and specify an AAA method. For more information, see "Configuring AAA." { For local authentication, you must also create local user accounts (including usernames and passwords), and specify the lan-access service for local users. { For RADIUS authentication, make sure the device and the RADIUS server can reach each other, and create user accounts on the RADIUS server. If you are using MAC-based accounts, make sure the username and password for each account are the same as the MAC address of each MAC authentication user. 2. Make sure the port security feature is disabled. For more information about port security, see "Configuring port security." Configuration task list Tasks at a glance (Required.) Enabling MAC authentication (Optional.) Specifying a MAC authentication domain (Optional.) Configuring the user account format (Optional.) Configuring MAC authentication timers (Optional.) Set the maximum number of concurrent MAC authentication users on the port Enabling MAC authentication You cannot enable MAC authentication on a port already in a link aggregation group or a service loopback group, or add a MAC authentication enabled port to a link aggregation group or a service loopback group. For MAC authentication to take effect on a port, you must enable it globally and on the port. To enable MAC authentication: Step 1. Enter system view. 2. Enable MAC authentication globally. 3. Enter interface view. Command system-view mac-authentication interface interface-type interface-number Remarks N/A By default, MAC authentication is disabled globally. N/A 79

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

79
For more information about configuring local authentication and RADIUS authentication, see
"
Configuring AAA
."
Configuration prerequisites
Before you configure MAC authentication, complete the following tasks:
1.
Configure an ISP domain and specify an AAA method. For more information, see "
Configuring
AAA
."
{
For local authentication, you must also create local user accounts (including usernames and
passwords), and specify the
lan-access
service for local users.
{
For RADIUS authentication, make sure the device and the RADIUS server can reach each other,
and create user accounts on the RADIUS server. If you are using MAC-based accounts, make
sure the username and password for each account are the same as the MAC address of each
MAC authentication user.
2.
Make sure the port security feature is disabled. For more information about port security, see
"
Configuring port security
."
Configuration task list
Tasks at a glance
(Required.)
Enabling MAC authentication
(Optional.)
Specifying a MAC authentication domain
(Optional.)
Configuring the user account format
(Optional.)
Configuring MAC authentication timers
(Optional.)
Set the maximum number of concurrent MAC authentication users on the port
Enabling MAC authentication
You cannot enable MAC authentication on a port already in a link aggregation group or a service
loopback group, or add a MAC authentication enabled port to a link aggregation group or a service
loopback group.
For MAC authentication to take effect on a port, you must enable it globally and on the port.
To enable MAC authentication:
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enable MAC authentication
globally.
mac-authentication
By default, MAC authentication is
disabled globally.
3.
Enter interface view.
interface
interface-type
interface-number
N/A