342
Keyword
Security mode
Description
mac-else-userlogin-s
ecure-ext
macAddressElseUse
rLoginSecureExt
Same as the macAddressElseUserLoginSecure mode
except that a port in this mode supports multiple 802.1X
and MAC authentication users.
secure
secure
In this mode, MAC address learning is disabled on the
port and you can configure MAC addresses by using the
mac-address static
and
mac-address dynamic
commands.
The port permits only frames sourced from the following
MAC addresses to pass:
•
Secure MAC addresses.
•
MAC addresses configured by using the
mac-address static
and
mac-address dynamic
commands.
userlogin
userLogin
In this mode, a port performs 802.1X authentication and
implements port-based access control.
If one 802.1X user passes authentication, all the other
802.1X users of the port can access the network without
authentication.
userlogin-secure
userLoginSecure
In this mode, a port performs 802.1X authentication and
implements MAC-based access control. The port
services only one user passing 802.1X authentication.
userlogin-secure-ext
userLoginSecureExt
Same as the userLoginSecure mode, except that this
mode supports multiple online 802.1X users.
userlogin-secure-or-
mac
macAddressOrUserL
oginSecure
This mode is the combination of the userLoginSecure
and macAddressWithRadius modes. In this mode, the
port allows one 802.1X authentication user and multiple
MAC authentication users to log in.
In this mode, the port performs 802.1X authentication
first. If 802.1X authentication fails, MAC authentication is
performed.
userlogin-secure-or-
mac-ext
macAddressOrUserL
oginSecureExt
Same as the macAddressOrUserLoginSecure mode,
except that a port in this mode supports multiple 802.1X
and MAC authentication users.
userlogin-withoui
userLoginWithOUI
Similar to the userLoginSecure mode. In addition, a port
in this mode also permits frames from a user whose MAC
address contains a specific OUI.
In this mode, the port performs OUI check at first. If the
OUI check fails, the port performs 802.1X authentication.
The port permits frames that pass OUI check or 802.1X
authentication.
Usage guidelines
Port security modes except for
userLogin
are supported only on the following ports:
•
Layer 2 Ethernet ports on the following modules:
HMIM-8GSW.
HMIM-24GSW.
HMIM-24GSWP.
SIC-4GSW.
SIC-4GSWP
•
Fixed Layer 2 Ethernet ports on the following routers:
MSR954 (JH296A/JH297A/JH298A/JH299A/JH373A).
Summary of Contents for FlexNetwork MSR Series
Page 1005: ...987 ...