vii
Traceroute ····································································································································································· 289
Ping operation ······························································································································································ 289
Traceroute operation ··················································································································································· 291
Configuring MAC authentication ··························································································································· 293
Overview ······································································································································································· 293
User account policies ·········································································································································· 293
Authentication procedures ·································································································································· 293
MAC authentication timers ································································································································· 294
Using MAC authentication with other features ········································································································· 294
VLAN assignment ················································································································································ 294
ACL assignment ··················································································································································· 294
Auth-Fail VLAN ···················································································································································· 294
Configuration prerequisites ········································································································································· 295
Configuration procedure ············································································································································· 295
Configuring MAC authentication globally ················································································································ 295
Configuring MAC authentication on a port ·············································································································· 297
MAC authentication configuration examples ············································································································ 298
Local MAC authentication configuration example··························································································· 298
ACL assignment configuration example············································································································ 301
Configuring 802.1X ··············································································································································· 310
Overview ······································································································································································· 310
802.1X architecture ············································································································································ 310
Access control methods ······································································································································ 310
802.1X timers ······················································································································································ 311
Configuration prerequisites ········································································································································· 311
Configuration guidelines ············································································································································· 311
Configuration procedure ············································································································································· 312
Configuring 802.1X globally ····································································································································· 312
Configuring 802.1X on a port ··································································································································· 313
Configuring an 802.1X guest VLAN ················································································································· 315
Configuring an Auth-Fail VLAN ························································································································· 316
802.1X configuration example ·································································································································· 317
ACL assignment configuration example ···················································································································· 323
Configuring port security ········································································································································ 332
Overview ······································································································································································· 332
Port security features ··········································································································································· 332
Port security modes ············································································································································· 332
Configuration guidelines ············································································································································· 334
Configuration procedures ··········································································································································· 334
Configuring global settings for port security ············································································································· 335
Configuring basic port security control ······················································································································ 336
Configuring secure MAC addresses ·························································································································· 337
Configuring advanced port security control ·············································································································· 338
Configuring permitted OUIs ········································································································································ 340
Port security configuration examples ························································································································· 340
Basic port security mode configuration example ····························································································· 340
Advanced port security mode configuration example ···················································································· 344
Configuring portal authentication ·························································································································· 350
Overview ······································································································································································· 350
Extended portal functions ··································································································································· 350
Portal system components ··································································································································· 350
Portal system using the local portal server ········································································································ 352