beautypg.com

Dot1x mac-authentication, Show dot1x advanced, Dot1x mac-authentication show dot1x advanced – Allied Telesis AT-S94 CLI (AT-8000S Series) User Manual

Page 388

background image

Page 387

Allied Telesis
AT-8000S-S94-3.0 Command Line Interface User’s Guide

Example

The following example forwards frames with source addresses that are not the supplicant address and sends
consecutive traps at intervals of 100 seconds.

dot1x mac-authentication

The mac-authentication Interface Configuration mode command enables authentication based on the station's
MAC address. Use the no form of this command to disable MAC authentication.

Syntax

dot1x mac-authentication {mac-only | mac-and-802.1x}

no dot1x mac-authentication

Parameters

mac-only — Enable authentication based on the station's MAC address only. 802.1X frames are ignored.

mac-and-802.1x — Enable 802.1X authentication and MAC address authentication on the interface.

Default Configuration

Disabled.

Command Mode

Interface configuration (Ethernet)

User Guidelines

Guest VLAN must be enabled when MAC authentication is enabled.

Static MAC addresses can't be authorized. Do not change authenticated MAC address to static address.

It is not recommended to delete authenticated MAC addresses.

Reauthentication must be enabled when working in this mode.

Example

The following example enables authentication based on the station's MAC address.

show dot1x advanced

The show dot1x advanced privileged EXEC mode command displays 802.1X advanced features for the switch
or for the specified interface.

console(config)# interface ethernet 1/16

console(config-if)# dot1x single-host-violation forward trap 100

console# configure

console(config)# interface ethernet 1/e1

console(config-if)# dot1x mac-authentication