Specifications

mac-authentication access-group
494
mac-authentication access-group
By applying the MAC access list to MAC-based authentication ports, sets whether
terminals are to be authenticated or not by using MAC addresses.
Syntax
To set or change information:
mac-authentication access-group <ACL ID>
To delete information:
no mac-authentication access-group
Input mode
(config)
Parameters
<ACL ID>
Specifies the identifier of the MAC access list that is to be set.
1. Default value when this parameter is omitted:
This parameter cannot be omitted.
2. Range of values:
Specify an access list name that is 3 to 31 characters. For details about the
characters that can be specified, see Specifiable values for parameters.
Default behavior
All terminals connected to MAC-based authentication ports are subject to authentication.
Impact on communication
None
When the change is applied
The change is applied immediately after setting values are changed.
Notes
1. All MAC-based authentication settings take effect when the mac-authentication
system-auth-control command is set.
2. See Table 24-1 Configuration commands and MAC-based authentication modes for
the authentication mode in which the command's settings are operable.
3. Implicit discard is present in a registered MAC access list. If the MAC address of a
terminal is not found in the MAC access list you have set, the terminal is not subject
to authentication due to implicit discard.
4. If a non-existent MAC access list is set, no operation is performed. The identifier of
the MAC access list is registered.
Related commands
mac-authentication system-auth-control
mac access-list extended