331
Examples
# Configure GigabitEthernet 1/0/1 to ignore the authorization information from the authentication
server.
<Sysname> system-view
[Sysname] interface gigabitethernet 1/0/1
[Sysname-GigabitEthernet1/0/1] port-security authorization ignore
Related commands
display port-security
port-security authorization-fail offline
Use
port-security authorization-fail offline
to enable the authorization-fail-offline feature.
Use
undo port-security authorization-fail offline
to disable the authorization-fail-offline feature.
Syntax
port-security authorization-fail offline
undo port-security authorization-fail offline
Default
The authorization-fail-offline feature is disabled. The device does not log off users who fail ACL
authorization.
Views
System view
Predefined user roles
network-admin
Usage guidelines
The authorization-fail-offline feature logs off port security users who fail ACL authorization.
A user fails ACL authorization in the following situations:
•
The device fails to authorize the specified ACL to the user.
•
The server assigns a nonexistent ACL to the user.
If this feature is disabled, the device does not log off users who fail ACL authorization. However, the
device outputs messages to report the failure.
Examples
# Enable the authorization-fail-offline feature.
<Sysname> system-view
[Sysname] port-security authorization-fail offline
Related commands
display port-security
port-security enable
Use
port-security enable
to enable port security.
Use
undo port-security enable
to disable port security.
Summary of Contents for FlexNetwork MSR Series
Page 1005: ...987 ...