show mac-authentication sessions

Displays MAC authentication sessions at the global and interface levels.
Syntax
show mac-authentication sessions { all | brief | stack-unit id | ethernet unit/slot/port }
Parameters
all
Displays MAC authentication sessions for all ports.
brief
Displays summary information for MAC authentication sessions.
ethernet unit/slot/port
Displays MAC sessions for the specified Ethernet interface.
stack-unit id
Displays MAC sessions for the specified stack unit.
Modes

Privileged EXEC mode

Usage Guidelines

A client session can have an IPv4 address and multiple IPv6 addresses. When multiple addresses exist, the show mac-authentication sessions command displays all addresses for the session.

The show mac-authentication sessions command displays the following information.

Output field Description
Port Port number.
MAC Addr MAC address of the client.
IP Addr IP address or addresses of the client (a session can have an IPv4 address and multiple IPv6 addresses). IP addresses of the authenticated host are only displayed when an IP ACL is applied to the interface based on the RADIUS server response.
Vlan VLAN ID.
Auth State Authentication state.
ACL Specific applied ACL.
Session Time Session time.
Age Age of the session.
Examples

The following example displays MAC authentication sessions for all interfaces.

device# show mac-authentication sessions all
-----------------------------------------------------------------------------------
Port    MAC               IP(v4/v6)            VLAN  Auth      ACL    Session   Age
        Addr              Addr                       State            Time         
-----------------------------------------------------------------------------------
1/1/1   0024.38c9.da40    fe80::224:38ff:fec9: 100   Yes       None   7400      Ena             
                          N/A                 
1/1/1   00aa.bbcc.dd00    fe80::2aa:bbff:fecc: 100   Yes       Yes    7400      Ena 
                          222::223            
                          100.100.100.10      

The following example displays MAC authentication sessions for a specified interface.

device# show mac-authentication sessions ethernet 1/1/2
---------------------------------------------------------------------------------
Port        MAC               IP              Vlan  Auth      ACL    Session  Age
            Addr              Addr                  State            Time
---------------------------------------------------------------------------------
1/1/2       0010.94ab.0021    192.85.1.2      300   Yes       Yes    100      Ena
 

The following example displays MAC authentication sessions in brief.

device# show mac-authentication sessions brief
--------------------------------------------------------------------------------------------
Port      Number of           Number of          Number of         Untagged         Dynamic
          Attempted Users     Authorized Users   Denied Users      VLAN Type        Port ACL
--------------------------------------------------------------------------------------------
1/1/2     1                   1                  0                 Radius-VLAN         No
1/1/3     0                   0                  0                 Auth-Default-VLAN   No
1/1/4     0                   0                  0                 Auth-Default-VLAN   No
1/1/5     0                   0                  0                 Auth-Default-VLAN   No
2/1/1     0                   0                  0                 Auth-Default-VLAN   No
2/1/2     0                   0                  0                 Auth-Default-VLAN   No
2/1/4     0                   0                  0                 Auth-Default-VLAN   No

History
Release version Command history
08.0.20 This command was introduced.
08.0.50 The command output was updated.
08.0.61 The command output was modified to display multiple IPv6 addresses for a session.
08.0.70 The command was modified to introduce the stack-unit id option.