Command Line Interface

4-126

4

Network Access (MAC Address Authentication)

Network Access authentication controls access to the network by authenticating the
MAC address of each host that attempts to connect to a switch port. Traffic received
from a specific MAC address is forwarded by the switch only if the source MAC
address is successfully authenticated by a central RADIUS server. While
authentication for a MAC address is in progress, all traffic is blocked until
authentication is completed. On successful authentication, the RADIUS server may
optionally assign VLAN and QoS settings for the switch port.

network-access max-mac-count

Use this command to set the maximum number of MAC addresses that can be
authenticated on a port interface via all forms of authentication. Use the no form of
this command to restore the default.
Syntax
network-access max-mac-count count
no network-access max-mac-count
count - The maximum number of authenticated MAC addresses allowed.
(Range: 1 to 2048; 0 for unlimited)
Default Setting
2048
Command Mode
Interface Configuration
Table 4-41 Network Access
Command Function Mode Page
network-access
max-mac-count
Sets a maximum number for authenticated MAC
addresses on an interface
IC 4-126
network-access mode Enables MAC authentication on an interface IC 4-127
mac-authentication
reauth-time
Sets the time period after which a connected MAC
address must be re-authenticated
GC 4-128
mac-authentication
max-mac-count
Sets a maximum number for mac-authentication
authenticated MAC addresses on an interface
IC 4-129
mac-authentication
intrusion-action
Determines the port response when a connected host fails
MAC authentication.
IC 4-128
show network-access Displays the MAC authentication settings for port
interfaces
PE 4-129
show network-access
mac-address-table
Displays information for entries in the secure MAC
address table
PE 4-130