126 
The device uses LLDP to identify voice users. For information about LLDP, see Layer 2—LAN 
Switching Configuration Guide. 
•  Enable voice VLAN on the port. 
For information about voice VLANs, see Layer 2—LAN Switching Configuration Guide. 
Configuration procedure 
To enable the MAC authentication critical voice VLAN feature on a port: 
 
Step Command Remarks 
1.  Enter system view. 
system-view 
N/A 
2.  Enter Ethernet interface 
view. 
interface 
interface-type 
interface-number
 
N/A 
3.  Enable the MAC 
authentication critical voice 
VLAN feature on a port. 
mac-authentication 
critical-voice-vlan 
By default, the MAC 
authentication critical voice VLAN 
feature is disabled on a port. 
 
Configuring periodic MAC reauthentication 
Overview 
Periodic MAC reauthentication reauthenticates online MAC authentication users at a 
user-configurable reauthentication interval. The reauthentication feature tracks the connection 
status of online users and updates the authorization attributes assigned by the server. The attributes 
include the ACL and VLAN. 
By default, the device logs off online MAC authentication users if no server is reachable for MAC 
reauthentication. The keep-online feature keeps authenticated MAC authentication users online 
when no server is reachable for MAC reauthentication. 
Configuration restrictions and guidelines 
When you configure periodic MAC reauthentication, follow these restrictions and guidelines: 
•  The server-assigned RADIUS Session-Timeout (attribute 27) and Termination-Action (attribute 
29) attributes together can affect the periodic MAC reauthentication feature. To display the 
server-assigned Session-Timeout and Termination-Action attributes, use the display 
mac-authentication connection command (see Security Command Reference). 
{  If the termination action is logging off users, periodic MAC reauthentication takes effect only 
when the periodic reauthentication timer is shorter than the session timeout timer. If the 
session timeout timer is shorter, the device logs off online authenticated users when the 
session timeout timer expires. 
{  If the termination action is reauthenticating users, the periodic MAC reauthentication 
configuration on the device cannot take effect. The device reauthenticates online MAC 
authentication users after the server-assigned session timeout timer expires. 
Support for the server configuration and assignment of session timeout timer and termination 
action depends on the server model. 
•  You can set the periodic reauthentication timer either in system view or in interface view by 
using the mac-authentication timer reauth-period command. A change to the periodic 
reauthentication timer applies to online users only after the old timer expires.