HP FlexNetwork 10500 Series Security Configuration Manual page 211

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

You can specify a port security mode when port security is disabled, but your configuration
cannot take effect.
Changing the port security mode of a port logs off the online users of the port.
Do not enable 802.1X authentication or MAC authentication on a port where port security is
configured.
The device supports the URL attribute assigned by a RADIUS server in the following port
security modes:
mac-authentication.
mac-else-userlogin-secure.
mac-else-userlogin-secure-ext.
userlogin-secure.
userlogin-secure-ext.
userlogin-secure-or-mac.
userlogin-secure-or-mac-ext.
userlogin-withoui.
During authentication, a user is redirected to the Web interface specified by the
server-assigned URL attribute. After the user passes the Web authentication, the RADIUS
server records the MAC address of the Web user and uses a DM (Disconnect Message) to log
off the Web user. When the user initiates 802.1X or MAC authentication again, it will pass the
authentication and come online successfully.
To enable a port security mode:
Step
1.
Enter system view.
2.
(Optional.) Set an OUI value
for user authentication.
3.
Enter Layer 2 Ethernet
interface view.
4.
Set the port security mode.
Command
system-view
port-security oui index
index-value mac-address
oui-value
interface interface-type
interface-number
port-security port-mode
{ autolearn |
mac-authentication |
mac-else-userlogin-secure |
mac-else-userlogin-secure-ext
| secure | userlogin |
userlogin-secure |
userlogin-secure-ext |
userlogin-secure-or-mac |
userlogin-secure-or-mac-ext |
userlogin-withoui }
197
Remarks
N/A
By default, no OUI value is
configured for user
authentication.
This command is required for the
userlogin-withoui mode.
You can set multiple OUIs, but
when the port security mode is
userlogin-withoui, the port
allows one 802.1X user and only
one user that matches one of the
specified OUIs.
N/A
By default, a port operates in
noRestrictions mode.
After enabling port security, you
can change the port security
mode of a port only when the port
is operating in noRestrictions (the
default) mode. To change the port
security mode for a port in any
other mode, first use the undo
port-security port-mode
command to restore the default
port security mode.

Advertisement

Table of Contents
loading

Table of Contents