EasyManuals Logo

ELTEX MES1000 User Manual

ELTEX MES1000
231 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #178 background imageLoading...
Page #178 background image
178 MES1000, MES2000 Ethernet Switches
Ethernet interface configuration mode commands
Command line request in Ethernet interface configuration mode appears as follows:
console(config-if)#
Table 5.205 Ethernet interface configuration mode commands
Command
Value/Default value
Action
dot1x host-mode
{multi-host | single-host |
multi-sessions}
-/ multi-host
Allow the presence of single/multiple clients on the authorized
802.1X port.
- multi-hostmultiple clients
- single-hostsingle client
- multi-sessionsmultiple sessions
dot1x violation-mode
{restrict | protect |
shutdown }
-/protect
Define the action that should be performed when the device
with MAC address, that differs from the client's MAC address,
attempts to access the interface.
- restrictpackets with MAC address, that differs from the
client's MAC address, are forwarded; the source address
learning is not performed
- protectpackets with MAC address, that differs from the
client's MAC address, are dropped
- shutdownport is disabled; packets with MAC address, that
differs from the client's MAC address, are dropped
SNMP trap message generation frequency, when unauthorized
packets arrive, equals to 1 second.
The command is ignored in the multiple hosts mode.
no dot1x
single-host-violation
Restore the default value.
dot1x guest-vlan enable
-/access denied
Allow unauthorized users of this interface to access the guest
VLAN.
The device should have at least one guest VLAN
authorized (dot1x guest-vlan command in VLAN
interface settings).
no dot1x guest-vlan enable
Deny unauthorized users of this interface to access the guest
VLAN.
dot1x mac-authentication
{mac-only |
mac-and-802.1x}
-/disabled
Enable authentication based on the user MAC addresses.
- mac-onlyenable authentication based on MAC addresses
only, 802.1х packets are ignored
- mac-and-802.1x—enable authentication based on 802.1х
and MAC addresses
- Guest VLAN should be enabled, when
authentication based on МАС address is used.
- There should be no static MAC address bindings.
- Re-authentication function should be enabled.
no dot1x mac-
authentication
Disable authentication based on the user MAC addresses.
dot1x radius-attributes
filter-id
-/disabled
Enable authentication based on ACL/assign QoS-Policy.
no dot1x radius-attributes
filter-id
Restore the default value.
dot1x radius-attributes
vlan
-/disabled
Enables Tunnel-Private-Group-ID (81) option processing in
RADIUS server messages.
no dot1x radius-attributes
vlan
Disables Tunnel-Private-Group-ID (81) option processing in
RADIUS server messages.
VLAN configuration mode commands
Command line request in VLAN interface configuration mode appears as follows:
console(config-if)#

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the ELTEX MES1000 and is the answer not in the manual?

ELTEX MES1000 Specifications

General IconGeneral
BrandELTEX
ModelMES1000
CategorySwitch
LanguageEnglish

Related product manuals