T
curity modes
able 15-1
Description of port se
On the port, if you want to…
Use the security mode…
autoLearn
Control MAC address learning
secure
userLogin
userLoginSecure
userLoginSecureExt
Perform 802.1X authentication
oginWithO
userL
UI
Perform MAC authentication
macAddressWithRadius
macAddressAndUserLoginSecure
And
Ext
macAddressAndUserLoginSecure
macAddressElseUserLoginSecure
Else
macAddressElseUserLoginSecureExt
macAddressOrUserLoginSecure
Perform a combination of MAC
authentication and 802.1X
authentication
cureExt
Or
macAddressOrUserLoginSe
These security mode naming rules may help you remember the modes:
z
userLogin
specifies 802.1X authentication and port-based access control.
userLogin
with
Secure
specifies 802.1X authentication and MAC-based access control.
macAddress
specifies MAC
z
z
authentication.
g both authentications.
r to turn to the authentication method following
Else
depends on the protocol type of
the authentication request.
z
In a security mode with
Or
, which authentication method is to be used depends on the protocol
2.1X users to be authenticated and serviced at the same time
.
z
And
specifies that both MAC authentication and 802.1X authentication are required. A user can
access the network only after passin
z
Else
specifies that the authentication method before
Else
is applied first. If the authentication
fails, whethe
type of the authentication request.
z
Ext
indicates allowing multiple 80
autoL
z
also configure secure MAC addresses by using the
can configure dynamic MAC addresses by using the
mac-address dynamic
ng the
mac-address static
or
mac-address dynamic
A port in
autoLearn
or
secure
mode allows only frames sourced from the MAC addresses that are in
the MAC address table to pass.
Figure 15-1
earn mode vs. secure mode
In
autoLearn
mode, a port can learn MAC addresses. These dynamically learned MAC addresses
are secure MAC addresses. You can
mac-address security
command. A secure MAC addresses never ages out by default. When the
number of secure MAC addresses reaches the upper limit, the port turns to
secure
mode. In
addition, you
command for a port in
autoLearn
mode.
z
In
secure
mode, MAC address learning is disabled on the port and you can configure static and
dynamic MAC addresses (by usi
command).
shows the packet processing on a port in autoLearn/secure mode and the mode transition.
15-2