72
Table 48 Configuration items
Item Description
Port Mode
mac and psk: MAC-based authentication must be performed on access users
first. If MAC-based authentication succeeds, an access user has to use the
pre-configured PSK to negotiate with the device. Access to the port is allowed
only after the negotiation succeeds.
Max User
Control the maximum number of users allowed to access the network through
the port.
MAC Authentication Select the
MAC Authentication
option.
Domain
Select an existing domain from the list.
The default domain is
system
. To create a domain, select
Authentication
>
AAA
from the navigation tree, click the
Domain Setup
tab, and type a new
domain name in the
Domain Name
field.
• The selected domain name applies to only the current wireless service,
and all clients accessing the wireless service use this domain for
authentication, authorization, and accounting.
• Do not delete a domain name in use. Otherwise, the clients that access
the wireless service will be logged out.
Preshared Key
• pass-phrase—Enter a PSK in the form of a character string. You should
enter a string that can be displayed and is of 8 to 63 characters.
• raw-key—Enter a PSK in the form of a hexadecimal number. You should
input a valid 64-bit hexadecimal number.
4. Configure psk:
Figure 49 Configuring psk port security
Table 49 Configuration items
Item Description
Port Mode
psk: An access user must use the pre-shared key (PSK) that is
pre-configured to negotiate with the device. The access to the port is
allowed only after the negotiation succeeds.
Max User
Control the maximum number of users allowed to access the network
through the port.
Preshared Key
• pass-phrase—Enter a PSK in the form of a character string. Enter a
string that can be displayed and is of 8 to 63 characters.
• raw-key—Enter a PSK in the form of a hexadecimal number. Enter a
valid 64-bit hexadecimal number.
5. Configure userlogin-secure-ext: