Authentication Commands 4

Network Access MAC Address Authentication

The Network Access feature controls host access to the network by authenticating its MAC address on the connected switch port. Traffic received from a specific MAC address is forwarded by the switch only if the source MAC address is successfully authenticated by a central RADIUS server. While authentication for a MAC address is in progress, all traffic is blocked until authentication is completed. On successful authentication, the RADIUS server may optionally assign VLAN settings for the switch port.

Table 4-36 Network Access

Command

Function

Mode

Page

network-access mode

Enables MAC authentication on an interface

IC

4-121

 

 

 

 

network-access

Sets a maximum for authenticated MAC addresses on an

IC

4-122

max-mac-count

interface

 

 

mac-authentication

Determines the port response when a connected host fails

IC

4-123

intrusion-action

MAC authentication.

 

 

mac-authentication

Sets a maximum for mac-authentication autenticated

IC

4-123

max-mac-count

MAC addresses on an interface

 

 

network-access dynamic-qos

Enables dynamic quality of service feature

IC

4-124

 

 

 

 

network-access

Enables dynamic VLAN assignment from a RADIUS

IC

4-124

dynamic-vlan

server

 

 

network-access guest-vlan

Specifies the guest VLAN

IC

4-125

 

 

 

 

network-access

Enables the link detection feature

IC

4-125

link-detection

 

 

 

network-access

Configures the link detection feature to detect and act

IC

4-125

link-detection link-down

upon link down events

 

 

network-access

Configures the link detection feature to detect and act

IC

4-125

link-detection link-up

upon link up events

 

 

network-access

Configures the link detection feature to detect and act

IC

4-125

link-detection link-up-down

upon both link-up and link-down events

 

 

mac-authentication

Sets the time period after which a connected MAC

GC

4-127

reauth-time

address must be re-authenticated

 

 

clear network-access

Clears authenticated MAC addresses from the address

PE

4-128

 

table

 

 

show network-access

Displays the MAC authentication settings for port

PE

4-128

 

interfaces

 

 

show network-access

Displays information for entries in the secure MAC

PE

4-129

mac-address-table

address table

 

 

network-access mode

Use this command to enable network access authentication on a port interface. Use the no form of this command to disable network access authentication.

Syntax

[no] network-access mode mac-authentication

4-121

Page 417
Image 417
Accton Technology ES3528M-SFP manual Network-access mode, Network Access Command Function Mode, 123