Configuring A Mac Authentication Critical Vlan - HP FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Step
1.
Enter system view.
2.
Enter Layer 2 Ethernet
interface view.
3.
Specify the MAC
authentication guest
VLAN on the port.
4.
(Optional.) Set the
authentication interval
for users in the MAC
authentication guest
VLAN.

Configuring a MAC authentication critical VLAN

You must configure the MAC authentication critical VLAN on a hybrid port. Before you configure the
MAC authentication critical VLAN on a hybrid port, complete the following tasks:
Enable MAC authentication globally and on the port.
Enable MAC-based VLAN on the port.
Create the VLAN to be specified as the MAC authentication critical VLAN.
Configure the VLAN as an untagged member on the port.
When you configure the MAC authentication critical VLAN on a port, follow the guidelines in
12.
Table 12 Relationships of the MAC authentication critical VLAN with other security features
Feature
Quiet feature of MAC
authentication
Super VLAN
Port intrusion protection
To configure the MAC authentication critical VLAN on a port:
Step
1.
Enter system view.
2.
Enter Layer 2 Ethernet
interface view.
Command
system-view
interface interface-type
interface-number
mac-authentication
guest-vlan guest-vlan-id
mac-authentication
guest-vlan auth-period
period-value
Relationship description
The MAC authentication critical VLAN feature has
higher priority.
When a user fails MAC authentication because
no RADIUS authentication server is reachable,
the user can access the resources in the critical
VLAN. The user's MAC address is not marked as
a silent MAC address.
You cannot specify a VLAN as both a super VLAN
and a MAC authentication critical VLAN.
The critical VLAN feature has higher priority than
the block MAC action but lower priority than the
shutdown port action of the port intrusion
protection feature.
Command
system-view
interface interface-type
interface-number
123
Remarks
N/A
N/A
By default, no MAC authentication guest
VLAN is configured.
You can configure only one MAC
authentication guest VLAN on a port.
The default setting is 30 seconds.
Reference
See
"Setting MAC
authentication
See Layer 2—LAN
Switching Configuration
Guide.
See
"Configuring port
security."
Remarks
N/A
N/A
Table
timers."

Advertisement

Table of Contents
loading

Table of Contents