HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 91

Displaying and maintaining MAC authentication, Local MAC authentication configuration example,

Page 91 highlights

Step 1. Enter system view. Command system-view 2. Enter interface view. interface interface-type interface-number 3. Set the maximum number of concurrent MAC authentication mac-authentication max-user users on the port user-number Remarks N/A N/A By default, the maximum number of concurrent MAC authentication users is 256. Displaying and maintaining MAC authentication Execute display commands in any view and reset commands in user view. Task Display MAC authentication information. Clear MAC authentication statistics. Command display mac-authentication [ interface interface-type interface-number ] reset mac-authentication statistics [ interface interface-type interface-number ] Local MAC authentication configuration example Network requirements As shown in Figure 33, configure local MAC authentication on port Ten-GigabitEthernet 1/1/5 to control Internet access, as follows: • Configure the device to detect whether a user has gone offline every 180 seconds, and if a user fails authentication, deny the user for 180 seconds. • Configure all users to belong to the ISP domain aabbcc, and specify local authentication for users in the domain. • Use the MAC address of each user as the username and password for authentication, and require the MAC addresses be hyphenated and in lower case. Figure 33 Network diagram Configuration procedure # Add a network access local user, configure both the username and password as the host's MAC address 00-e0-fc-12-34-56, and specify the LAN access service for the account. system-view 82

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

82
Step
Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter interface view.
interface
interface-type
interface-number
N/A
3.
Set the maximum number of
concurrent MAC authentication
users on the port
mac-authentication max-user
user-number
By default, the maximum number
of concurrent MAC
authentication users is 256.
Displaying and maintaining MAC authentication
Execute
display
commands in any view and
reset
commands in user view.
Task
Command
Display MAC authentication information.
display mac-authentication
[
interface
interface-type
interface-number
]
Clear MAC authentication statistics.
reset mac-authentication statistics
[
interface
interface-type
interface-number
]
Local MAC authentication configuration example
Network requirements
As shown in
Figure 33
, configure local MAC authentication on port Ten-GigabitEthernet 1/1/5 to
control Internet access, as follows:
Configure the device to detect whether a user has gone offline every 180 seconds, and if a user fails
authentication, deny the user for 180 seconds.
Configure all users to belong to the ISP domain
aabbcc
, and specify local authentication for users
in the domain.
Use the MAC address of each user as the username and password for authentication, and require
the MAC addresses be hyphenated and in lower case.
Figure 33
Network diagram
Configuration procedure
# Add a network access local user, configure both the username and password as the host's MAC
address 00-e0-fc-12-34-56, and specify the LAN access service for the account.
<Device> system-view