Dot1x mac-authentication, Show dot1x advanced, Dot1x mac-authentication show dot1x advanced – Allied Telesis AT-S94 CLI (AT-8000S Series) User Manual
Page 388
Page 387
Allied Telesis
AT-8000S-S94-3.0 Command Line Interface User’s Guide
Example
The following example forwards frames with source addresses that are not the supplicant address and sends
consecutive traps at intervals of 100 seconds.
dot1x mac-authentication
The mac-authentication Interface Configuration mode command enables authentication based on the station's
MAC address. Use the no form of this command to disable MAC authentication.
Syntax
dot1x mac-authentication {mac-only | mac-and-802.1x}
no dot1x mac-authentication
Parameters
•
mac-only — Enable authentication based on the station's MAC address only. 802.1X frames are ignored.
•
mac-and-802.1x — Enable 802.1X authentication and MAC address authentication on the interface.
Default Configuration
Disabled.
Command Mode
Interface configuration (Ethernet)
User Guidelines
Guest VLAN must be enabled when MAC authentication is enabled.
Static MAC addresses can't be authorized. Do not change authenticated MAC address to static address.
It is not recommended to delete authenticated MAC addresses.
Reauthentication must be enabled when working in this mode.
Example
The following example enables authentication based on the station's MAC address.
show dot1x advanced
The show dot1x advanced privileged EXEC mode command displays 802.1X advanced features for the switch
or for the specified interface.
console(config)# interface ethernet 1/16
console(config-if)# dot1x single-host-violation forward trap 100
console# configure
console(config)# interface ethernet 1/e1
console(config-if)# dot1x mac-authentication