H3C Low-End Ethernet Switches Configuration Guide(V1.01)

HomeSupportSwitchesH3C S3100 Switch SeriesConfigure & DeployConfiguration ExamplesH3C Low-End Ethernet Switches Configuration Guide(V1.01)
Table of Contents
Related Documents
19-MAC Authentication Configuration Guide
Title Size Download
19-MAC Authentication Configuration Guide 45.89 KB

Configuring MAC Authentication

MAC authentication provides a way for authenticating users based on ports and MAC addresses, without requiring any client software to be installed on the hosts. Once detecting a new MAC address, a switch with MAC authentication configured will initiate the authentication process. During authentication, the user does not need to enter any username and password manually.

MAC authentication can be implemented locally or by a RADIUS server.

 After determining the authentication mode, you can select one of the following username types as required:

l          MAC address, where the MAC address of a user serves as the username for authentication (you can use the mac-authentication authmode usernameasmacaddress usernameformat command to set the MAC address format).

l          Fixed username, where the same username and password preconfigured on the switch are used to authenticate all users. In addition, the number of concurrent users is limited with this username type. This username type is not recommended.

Network Diagram

Figure 1-1 Network diagram for configuring local MAC authentication

 

Networking and Configuration Requirements

As illustrated in Figure 1-1, a supplicant is connected to the switch through port Ethernet 1/0/2.

l          MAC authentication is required on port Ethernet 1/0/2 to control user access to the Internet.

l          All users belong to domain aabbcc.net. The authentication is performed locally and the MAC address of the PC (00-0d-88-f6-44-c1) is used as both the username and password.

Applicable Product Matrix

Product series

Software version

Hardware version

S5600 series

Release 1510, Release1602

All versions

S5100-SI/EI series

Release 2200, Release2201

All versions

S3600-SI/EI series

Release 1510, Release1602

All versions

S3100-EI series

Release 2104, Release 2107

All versions

S3100-C-SI series

S3100-T-SI series

Release 0011, Release 2102, Release 2107

All versions

S3100-52P

Release 1500, Release 1602

S3100-52P

 

Configuration Procedure

# Enable MAC authentication for port Ethernet 1/0/2.

<H3C> system-view

[H3C] mac-authentication interface Ethernet 1/0/2

# Specify the MAC authentication username type as MAC address and the MAC address format as with-hyphen.

[H3C] mac-authentication authmode usernameasmacaddress usernameformat with-hyphen

# Create a local user account.

l          Specify the username and password.

[H3C] local-user 00-0d-88-f6-44-c1

[H3C-luser-00-0d-88-f6-44-c1] password simple 00-0d-88-f6-44-c1

l          Set the service type to lan-access.

[H3C-luser-00-0d-88-f6-44-c1] service-type lan-access

[H3C-luser-00-0d-88-f6-44-c1] quit

# Create an ISP domain named aabbcc.net.

[H3C] domain aabbcc.net

New Domain added.

# Configure domain aabbcc.net to perform local authentication.

[H3C-isp-aabbcc.net] scheme local

[H3C-isp-aabbcc.net] quit

# Specify aabbcc.net as the ISP domain for MAC authentication.

[H3C] mac-authentication domain aabbcc.net

# Enable MAC authentication globally.

[H3C] mac-authentication

After configuring the above command, your MAC authentication configuration will take effect immediately, and Only the user with the MAC address of 00-0d-88-f6-44-c1 is allowed to access the Internet through port Ethernet 1/0/2. Note that enabling authentication globally is usually the last step in configuring access control related features. Otherwise, valid users may be denied access to the networks because of incomplete configuration.

Complete Configuration

#

 domain default enable aabbcc.net

#

 MAC-authentication

 MAC-authentication domain aabbcc.net

 MAC-authentication authmode usernameasmacaddress usernameformat with-hyphen #

domain aabbcc.net

#

local-user 00-0d-88-f6-44-c1

 password simple 00-0d-88-f6-44-c1

 service-type lan-access

#

Precautions

l          You cannot configure the maximum number of MAC addresses that can be learnt on a MAC authentication enabled port, or enable MAC authentication on a port that is configured with the maximum number of MAC addresses that can be learnt.

l          You cannot configure port security on a MAC authentication enabled port, or enable MAC authentication on a port that is configured with port security.

  • Cloud & AI
  • InterConnect
  • Intelligent Computing
  • Security
  • SMB Products
  • Intelligent Terminal Products
  • Product Support Services
  • Technical Service Solutions
All Services
  • Resource Center
  • Policy
  • Online Help
All Support
  • Become a Partner
  • Partner Resources
  • Partner Business Management
All Partners
  • Profile
  • News & Events
  • Online Exhibition Center
  • Contact Us
All About Us
新华三官网