1-14
Keyword Security mode Description
mac-and-userlogin-sec
ure
macAddressAndUser
LoginSecure
In this mode, users trying to assess the
network through the port must first pass MAC
address authentication and then 802.1x
authentication.
In this mode, only one user can access the
network through the port at a time.
mac-and-userlogin-sec
ure-ext
macAddressAndUser
LoginSecureExt
This mode is similar to the
macAddressAndUserLoginSecure mode,
except that in this mode, more than one user
can access the network through the port in this
mode.
mac-authentication
macAddressWithRad
ius
In this mode, MAC address authentication is
applied on users trying to access the network.
mac-else-userlogin-se
cure
macAddressElseUse
rLoginSecure
In this mode, MAC address authentication is
first applied on users. If the authentication
succeeds, the users can access the network
successfully. If not, 802.1x authentication is
applied.
In this mode, only one 802.1x-authenticated
user can access the network through the port.
But at the same time, there can be more than
one MAC-address-authenticated user on the
port.
mac-else-userlogin-se
cure-ext
macAddressElseUse
rLoginSecureExt
This mode is similar to the
macAddressElseUserLoginSecure mode,
except that in this mode, there can be more
than one 802.1x-authenticated user on the
port.
secure secure
In this mode, MAC address learning is
disabled on the port. The port permits packets
whose source MAC addresses are static and
dynamic MAC addresses that were configured
manually.
When the port mode changes from autolearn
to secure, the security MAC addresses that
were learned in the autolearn mode are
permitted to pass through the port.
userlogin userlogin
In this mode, 802.1x authentication is applied
on users trying to access the network through
the current port.
userlogin-secure userLoginSecure
In this mode, MAC-based 802.1x
authentication is applied on users trying to
access the network through the port. The port
will be enabled when the authentication
succeeds and allow packets from
authenticated users to pass through.
In this mode, only one 802.1x-authenticated
user can access the network through the port.
When the security mode of the port changes
from noRestriction to this mode, the old
dynamic MAC address entries and
authenticated MAC address entries kept on
the port are deleted automatically.