98
If a user in the guest VLAN passes MAC authentication, the user is removed from the guest VLAN and
can access all authorized network resources. If not, the user is still in the MAC authentication guest
VLAN.
A hybrid port is always assigned to a guest VLAN as an untagged member. After the assignment, do not
re-configure the port as a tagged member in the VLAN.
MAC authentication configuration task list
Task Remarks
Basic configuration for MAC
authentication
Configuring MAC authentication globally
Required
Configuring MAC authentication on a port
Required
Specifying an authentication domain for MAC authentication users
Optional
Configuring a MAC authentication guest VLAN
Optional
Basic configuration for MAC authentication
Configuration prerequisites
•
Create and configure an authentication domain, also called "an ISP domain."
•
For local authentication, create local user accounts, and specify the
lan-access
service for the
accounts.
•
For RADIUS authentication, check that the device and the RADIUS server can reach each other, and
create user accounts on the RADIUS server.
If you are using MAC-based accounts, make sure that the username and password for each account is
the same as the MAC address of the MAC authentication users.
Configuration procedure
MAC authentication can take effect on a port only when it is enabled globally and on the port.
Configuring MAC authentication globally
To do…
Use the command…
Remarks
1.
Enter system view.
system-view
—
2.
Enable MAC
authentication globally.
mac-authentication
Required.
Disabled by default.
3.
Configure MAC
authentication timers.
mac-authentication
timer
{
offline-
detect
offline-detect-value
|
quiet
quiet-
value
|
server-timeout
server-timeout-
value
}
Optional.
By default, the offline detect timer
is 300 seconds, the quiet timer is
60 seconds, and the server
timeout timer is 100 seconds.