Command Manual (For Soliton) – MAC Address Authentication
H3C S3100 Series Ethernet Switches
Chapter 1 MAC Address Authentication
Configuration Commands
1-12
Caution:
z
If more than one client are connected to a port, you cannot configure a Guest VLAN
for this port.
z
When a Guest VLAN is configured for a port, only one MAC address authentication
user can access the port. Even if you set the limit on the number of MAC address
authentication users to more than one, the configuration does not take effect.
z
The
undo vlan
command cannot be used to remove the VLAN configured as a
Guest VLAN. If you want to remove this VLAN, you must remove the Guest VLAN
configuration for it. Refer to the VLAN module in this manual for the description on
the
undo vlan
command.
z
Only one Guest VLAN can be configured for a port, and the VLAN configured as the
Guest VLAN must be an existing VLAN. Otherwise, the Guest VLAN configuration
does not take effect. If you want to change the Guest VLAN for a port, you must
remove the current Guest VLAN and then configure a new Guest VLAN for this port.
z
802.1x authentication cannot be enabled for a port configured with a Guest VLAN.
z
The Guest VLAN function for MAC address authentication does not take effect
when port security is enabled.
Related commands:
mac-authentication timer guest-vlan-reauth
.
Examples
# Configure VLAN 4 as the Guest VLAN for Ethernet 1/0/1.
<Sysname> system-view
System View: return to User View with Ctrl+Z.
[Sysname] interface Ethernet 1/0/1
[Sysname-Ethernet1/0/1] mac-authentication guest-vlan 4
1.2.2 mac-authenticiaon intrusion-mode block-mac
Syntax
mac-authenticiaon intrusion-mode block-mac enable
undo mac-authenticiaon intrusion-mode block-mac enable
View
Ethernet port view
Parameter
None