HP 6125XLG R2306-HP 6125XLG Blade Switch Security Configuration Guide - Page 98

Controlling MAC address learning, Performing 802.1X authentication

Page 98 highlights

Controlling MAC address learning • autoLearn A port in this mode can learn MAC addresses. The automatically learned MAC addresses are not added to the MAC address table as dynamic MAC address, but to the secure MAC address table as secure MAC addresses. You can also configure secure MAC addresses by using the port-security mac-address security command. A port in autoLearn mode allows frames sourced from secure MAC addresses and MAC addresses configured by using the mac-address dynamic and mac-address static commands to pass. When the number of secure MAC addresses reaches the upper limit, the port transitions to secure mode. • secure MAC address learning is disabled on a port in secure mode. You configure MAC addresses by using the mac-address static and mac-address dynamic commands. For more information about configuring MAC address table entries, see Layer 2-LAN Switching Configuration Guide. A port in secure mode allows only frames sourced from secure MAC addresses and MAC addresses configured by using the mac-address dynamic and mac-address static commands to pass. Performing 802.1X authentication • userLogin A port in this mode performs 802.1X authentication and implements port-based access control. The port can service multiple 802.1X users. Once an 802.1X user passes authentication on the port, any subsequent 802.1X users can access the network through the port without authentication. • userLoginSecure A port in this mode performs 802.1X authentication and implements MAC-based access control. The port services only one user passing 802.1X authentication. • userLoginSecureExt This mode is similar to the userLoginSecure mode except that this mode supports multiple online 802.1X users. • userLoginWithOUI This mode is similar to the userLoginSecure mode. The difference is that a port in this mode also permits frames from one user whose MAC address contains a specific OUI. For wired users, the port performs 802.1X authentication upon receiving 802.1X frames, and performs OUI check upon receiving non-802.1X frames. NOTE: As defined by the IEEE, an OUI is the first 24 bits of the MAC address, which uniquely identifies a device vendor. Performing MAC authentication macAddressWithRadius: A port in this mode performs MAC authentication, and services multiple users. Performing a combination of MAC authentication and 802.1X authentication • macAddressOrUserLoginSecure 89

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276

89
Controlling MAC address learning
autoLearn
A port in this mode can learn MAC addresses. The automatically learned MAC addresses are not
added to the MAC address table as dynamic MAC address, but to the secure MAC address table
as secure MAC addresses. You can also configure secure MAC addresses by using the
port-security mac-address security
command.
A port in autoLearn mode allows frames sourced from secure MAC addresses and MAC addresses
configured by using the
mac-address dynamic
and
mac-address static
commands to pass.
When the number of secure MAC addresses reaches the upper limit, the port transitions to secure
mode.
secure
MAC address learning is disabled on a port in secure mode. You configure MAC addresses by
using the
mac-address static
and
mac-address dynamic
commands. For more information about
configuring MAC address table entries, see
Layer 2—LAN Switching Configuration Guide
.
A port in secure mode allows only frames sourced from secure MAC addresses and MAC
addresses configured by using the
mac-address dynamic
and
mac-address static
commands to
pass.
Performing 802.1X authentication
userLogin
A port in this mode performs 802.1X authentication and implements port-based access control.
The port can service multiple 802.1X users. Once an 802.1X user passes authentication on the
port, any subsequent 802.1X users can access the network through the port without
authentication.
userLoginSecure
A port in this mode performs 802.1X authentication and implements MAC-based access control.
The port services only one user passing 802.1X authentication.
userLoginSecureExt
This mode is similar to the userLoginSecure mode except that this mode supports multiple online
802.1X users.
userLoginWithOUI
This mode is similar to the userLoginSecure mode. The difference is that a port in this mode also
permits frames from one user whose MAC address contains a specific OUI.
For wired users, the port performs 802.1X authentication upon receiving 802.1X frames, and
performs OUI check upon receiving non-802.1X frames.
NOTE:
As defined by the IEEE, an OUI is the first 24 bits of the MAC address, which uniquely identifies a
device vendor.
Performing MAC authentication
macAddressWithRadius: A port in this mode performs MAC authentication, and services multiple users.
Performing a combination of MAC authentication and 802.1X authentication
macAddressOrUserLoginSecure