Product guide
4-34
Web and MAC Authentication
Configuring MAC Authentication
Syntax: aaa port-access mac-based [e] < port-list > [server-timeout <1 - 300>]
Specifies the period, in seconds, the switch waits for a
server response to an authentication request. Depend-
ing on the current max-requests value, the switch sends
a new attempt or ends the authentication session.
(Default: 30seconds)
Syntax: aaa port-access mac-based [e] < port-list > [unauth-vid <vid>]
no aaa port-access mac-based [e] < port-list > [unauth-vid]
Specifies the VLAN to use for a client that fails authen-
tication. If unauth-vid is 0, no VLAN changes occur.
Use the no form of the command to set the unauth-vid to 0.
(Default: 0)
Syntax: aaa port-access <port-list > controlled-directions <both | in>
After you enable MAC-based authentication on specified
ports, you can use the aaa port-access controlled-directions
command to configure how a port transmits traffic
before it successfully authenticates a client and enters
the authenticated state.
both (default): Incoming and outgoing traffic is blocked
on a port configured for MAC authentication before
authentication occurs.
in: Incoming traffic is blocked on a port configured for
MAC authentication before authentication occurs. Out-
going traffic with unknown destination addresses is
flooded on unauthenticated ports configured for web
authentication.