1-16
Keyword
Security mode
Description
userlogin-secure userLoginSecure
In this mode, MAC-based 802.1x
authentication is applied on users trying to
access the network through the port. The port
will be enabled when the authentication
succeeds and allow packets from
authenticated users to pass through.
In this mode, only one 802.1x-authenticated
user can access the network through the port.
When the security mode of the port changes
from
noRestriction
to this mode, the old
dynamic MAC address entries and
authenticated MAC address entries kept on
the port are deleted automatically.
userlogin-secure-ext userLoginSecureExt
This mode is similar to the
userLoginSecure
mode, except that in this mode, there can be
more than one 802.1x-authenticated user on
the port.
userlogin-secure-or-m
ac
macAddressOrUserL
oginSecure
MAC address authentication and 802.1x
authentication can coexist on a port, with
802.1x authentication having higher priority.
802.1x authentication can be applied on users
who have already passed MAC address
authentication.
However, users who have already passed
802.1x authentication do not need to go
through MAC address authentication.
In this mode, only one 802.1x-authenticated
user can access the network through the port.
However, there can be more than one
MAC-address-authenticated user on the port.
userlogin-secure-or-m
ac-ext
macAddressOrUserL
oginSecureExt
This mode is similar to the
macAddressOrUserLoginSecure
mode,
except that in this mode, there can be more
than one 802.1x-authenticated user on the
port.
userlogin-withoui userLoginWithOUI
Similar to the
userLoginSecure
mode, in this
mode, there can be only one
802.1x-authenticated user on the port.
However, the port also allows packets with the
OUI address to pass through.
When the security mode of the port changes
from
noRestriction
to this mode, the old
dynamic MAC address entries and
authenticated MAC address entries kept on
the port are deleted automatically.
Description
Use the
port-security port-mode
command to set the security mode of the port.
Use the
undo port-security port-mode
command to restore the default mode.
By default, the port is in the
noRestriction
mode, namely access to the port is not restricted.
Summary of Contents for 5500-EI PWR
Page 43: ...2 6...
Page 76: ...1 17...
Page 228: ...ii stp transmit limit 1 44 vlan mapping modulo 1 45 vlan vpn tunnel 1 46...
Page 477: ...5 24 Sysname vlan 2 Sysname vlan2 service type multicast...
Page 503: ...2 3 System View return to User View with Ctrl Z Sysname dot1x url http 192 168 19 23...
Page 519: ...iii...
Page 597: ...2 2 security policy server 192 168 0 1 user name format without domain...
Page 648: ...1 9 Examples Clear static ARP entries Sysname reset arp static...
Page 663: ...4 3 Sysname resilient arp interface vlan interface 2...
Page 767: ...1 28 From 12 00 Jan 1 2008 to 12 00 Jun 1 2008...
Page 1111: ...ii xmodem get 3 18...
Page 1314: ...A 44 Z...