Support for authenticating multiple MAC sessions on an interface

Flexible authentication allows multiple MAC addresses to be authenticated or denied on each interface.

By default, the number of MAC sessions that can be authenticated on a single interface is two and can be changed using the authentication max-sessions command. The maximum number of authenticated MAC sessions on an interface depends on the RUCKUS ICX device and dynamic ACL assignments. If RADIUS assigns dynamic ACLs to at least one client on the interface, the maximum number of MAC sessions that can be authenticated is limited to 32 in all FastIron devices.

If a dynamic ACL is not assigned to any of the clients on the interface, the maximum number of MAC addresses that can be authenticated varies depending on the RUCKUS ICX device as specified in Maximum number of authenticated MAC sessions per port on various platforms. System reload is not required for the changes to take effect. However, existing sessions on the interface are cleared for the changes to take effect.

Maximum number of authenticated MAC sessions per port on various platforms

Supported platforms Maximum number of MAC sessions per port when none of the clients has dynamic ACL Maximum number of MAC sessions per port when at least one client has dynamic ACL
ICX 7750 1024 32
ICX 7450 1024 32
ICX 7250 1024 32

The system limit for authenticated MAC sessions also varies and depends on the RUCKUS ICX device and dynamic ACL assignments.

Maximum number of authenticated MAC sessions per system (standalone or stack) on various platforms

Supported platforms Maximum number of MAC sessions per system when none of the clients has dynamic ACL Maximum number of MAC sessions per system when at least one client has dynamic ACL
ICX 7750 1536 512
ICX 7450 1536 512
ICX 7250 1536 512