iv
Port security ····················································································································································· 79
Overview ·················································································································································· 79
Port security settings ································································································································ 80
Port security features ······························································································································· 82
Secure MAC addresses ··························································································································· 83
Portal ································································································································································ 83
Portal authentication server ····················································································································· 84
Portal Web server ···································································································································· 85
Local portal Web server ··························································································································· 85
Portal-free rules ········································································································································ 88
Interface policy ········································································································································· 88
ISP domains ····················································································································································· 89
RADIUS ··························································································································································· 90
RADIUS protocol ······································································································································ 90
Enhanced RADIUS features ···················································································································· 90
Log features ·································································································· 92
Log levels ················································································································································· 92
Log destinations ······································································································································· 92
Configuration examples ················································································ 93
Device maintenance examples ························································································································ 93
System time configuration example ········································································································· 93
Administrators configuration example ······································································································ 93
Stack configuration example ···················································································································· 94
NTP configuration example ······················································································································ 96
SNMP configuration example ··················································································································· 97
Network services configuration examples ········································································································ 97
Ethernet link aggregation configuration example ····················································································· 97
Port isolation configuration example ········································································································ 98
VLAN configuration example ···················································································································· 99
Voice VLAN configuration example ········································································································ 100
MAC address entry configuration example ···························································································· 101
MSTP configuration example ················································································································· 101
LLDP configuration example ·················································································································· 103
DHCP snooping configuration example ································································································· 103
Static ARP entry configuration example ································································································· 104
Static DNS configuration example ········································································································· 105
Dynamic DNS configuration example ···································································································· 106
DDNS configuration example with www.3322.org ················································································· 107
Static IPv6 address configuration example ···························································································· 108
ND configuration example ······················································································································ 109
Port mirroring configuration example ····································································································· 110
IPv4 static route configuration example ································································································· 111
IPv4 local PBR configuration example ··································································································· 112
IGMP snooping configuration example ·································································································· 112
MLD snooping configuration example ···································································································· 114
DHCP configuration example ················································································································· 115
Password authentication enabled Stelnet server configuration example ··············································· 117
QoS configuration example ···························································································································· 118
Security configuration examples ···················································································································· 119
ACL-based packet filter configuration example ······················································································ 119
Static IPv4 source guard configuration example ···················································································· 121
802.1X RADIUS authentication configuration example·········································································· 122
802.1X local authentication configuration example ················································································ 123
RADIUS-based MAC authentication configuration example ·································································· 124
RADIUS-based port security configuration example ·············································································· 126
Direct portal authentication configuration example ················································································ 128
Re-DHCP portal authentication configuration example·········································································· 130
Cross-subnet portal authentication configuration example ···································································· 132
Direct portal authentication using local portal Web server configuration example ································· 134
AAA for SSH users by a TACACS server configuration example ·························································· 136