beautypg.com

Brocade Multi-Service IronWare Security Configuration Guide (Supporting R05.6.00) User Manual

Page 300

background image

282

Multi-Service IronWare Security Configuration Guide

53-1003035-02

Displaying multi-device port authentication information

6

Syntax: show auth-mac-address detail

Displaying multi-device port authentication information for a specific
MAC address or port

To display authentication information for a specific MAC address or port, enter a command such as
the following.

Syntax: show auth-mac-address mac-address | ip-address | slot/portnum

The ip-address parameter lists the MAC address associated with the specified IP address.

The slot/portnum parameter lists the MAC addresses on the specified port.

The following table describes the information displayed by the show auth-mac-address command
for a specified MAC address or port.

DOS attack protection

Whether denial of service attack protection has been enabled for multi-device
port authentication, limiting the rate of authentication attempts sent to the
RADIUS server.

Accepted MAC Addresses

The number of MAC addresses that have been successfully authenticated.

Rejected MAC Addresses

The number of MAC addresses for which authentication has failed.

Aging of MAC-sessions

Whether software aging of MAC addresses is enabled.

Max-Age of MAC-sessions

The configured software aging period.

Port move-back VLAN

The VLAN that the port reverts to when the RADIUS-assigned dynamic VLAN
expires.

MAC Filter applied

Whether a MAC filter has been applied to this port to specify pre-authenticated
MAC addresses.

MAC Table

The MAC addresses learned on the port.

TABLE 41

Output from the show auth-mac-address address command

This field...

Displays...

MAC or IP Address

The MAC address for which information is displayed. If the packet for which
multi-device port authentication was performed also contained an IP address,
then the IP address is displayed as well.

Port

The port on which the MAC address was learned.

VLAN

The VLAN to which the MAC address was assigned.

Access

Whether or not the MAC address was allowed or denied access into the
network.

Age

The age of the MAC address entry in the authenticated MAC address list.

TABLE 40

Output from the show authenticated-mac-address command (Continued)

This field...

Displays...

Brocade# show auth-mac-address 0007.e90f.eaa1

-------------------------------------------------------------------------------

MAC/IP Address Port Vlan Access Age

-------------------------------------------------------------------------------

00A1.0010.2000 1/18 1 Allowed 0