mac-authentication auth-filter

Applies the specified filter on the interface and the MAC addresses defined in the filter (MAC filter) do not have to go through authentication.
Syntax
mac-authentication auth-filter filter-id vlan-id
no mac-authentication auth-filter filter-id vlan-id
Command Default

There are no filters applied on the interface.

Parameters
filter-id
Specifies the identification number of the filter to be applied on the interface.
vlan-id
Specifies the identification number of the VLAN to which the filter is applied.
Modes

Interface configuration mode

Usage Guidelines

The no form of this command disables this functionality.

A client can be authenticated in an untagged VLAN or tagged VLAN using the MAC address filter for MAC authentication. If auth-filter has tagged VLAN configuration, the clients are authenticated in auth-default VLAN and tagged VLAN provided in auth-filter. The clients authorized in auth-default VLAN allow both untagged and tagged traffic.

If the VLAN is not specified in the command, the auth-default VLAN is used.

Examples

The following example applies the MAC address filter on VLAN 2.

device(config)# authentication
device(config-authen)# interface ethernet 1/1/1
device(config-if-e1000-1/1/1)# mac-auth auth-filter 1 2
History
Release version Command history
08.0.20 This command was introduced.