Support for authenticating multiple MAC sessions on an interface
Flexible authentication allows multiple MAC addresses to be authenticated or denied on each interface.
By default, the number of MAC sessions that can be authenticated on a single interface
is two and can be changed using the
authentication max-sessions command. The maximum number of authenticated MAC sessions on an interface depends
on the
RUCKUS ICX device and dynamic ACL assignments. If RADIUS assigns dynamic ACLs to at least one
client on the interface, the maximum number of MAC sessions that can be authenticated
is limited to 32 in all FastIron devices.
If a dynamic ACL is not assigned to any of the clients on the interface, the maximum number of MAC addresses that can be authenticated varies depending on the RUCKUS ICX device as specified in Maximum number of authenticated MAC sessions per port on various platforms. System reload is not required for the changes to take effect. However, existing sessions on the interface are cleared for the changes to take effect.
Maximum number of authenticated MAC sessions per port on various platforms
| Supported platforms | Maximum number of MAC sessions per port when none of the clients has dynamic ACL | Maximum number of MAC sessions per port when at least one client has dynamic ACL |
|---|---|---|
| ICX 7750 | 1024 | 32 |
| ICX 7450 | 1024 | 32 |
| ICX 7250 | 1024 | 32 |
The system limit for authenticated MAC sessions also varies and depends on the RUCKUS ICX device and dynamic ACL assignments.
Maximum number of authenticated MAC sessions per system (standalone or stack) on various platforms
| Supported platforms | Maximum number of MAC sessions per system when none of the clients has dynamic ACL | Maximum number of MAC sessions per system when at least one client has dynamic ACL |
|---|---|---|
| ICX 7750 | 1536 | 512 |
| ICX 7450 | 1536 | 512 |
| ICX 7250 | 1536 | 512 |