beautypg.com

Brocade FastIron Ethernet Switch Security Configuration Guide User Manual

Page 252

background image

The filter-num command identifies the MAC address filter. The maximum number of supported MAC
address filters is determined by the mac-filter-sys default or configured value.

The dot1x auth-filterfilter-list command binds MAC address filters to a port.

The following rules apply when using the dot1x auth-filter command:

• When you add filters to or modify the dot1x auth-filter , the system clears all 802.1X sessions on

the port. Consequently, all users that are logged in will need to be re-authenticated.

• The maximum number of filters that can be bound to a port is limited by the mac-filter-port default

or configured value.

• The filters must be applied as a group. For example, if you want to apply four filters to an interface,

they must all appear on the same command line.

• You cannot add or remove individual filters in the group. To add or remove a filter on an interface,

apply the filter group again containing all the filters you want to apply to the port.

If you apply a filter group to a port that already has a filter group applied, the older filter group is
replaced by the new filter group.

Defining MAC Address Filters

252

FastIron Ethernet Switch Security Configuration Guide

53-1003088-03