Enabling MAC Authentication
The following steps enable MAC authentication and include certain Flexible authentication
configurations specific to MAC authentication.
- Enter the
configure terminalcommand to enter global configuration mode. - Enter the
authenticationcommand to enter authentication mode. - Enter the
mac-authentication enablecommand to enable MAC authentication.Note: Ports that are members of the auth-default VLAN cannot be enabled for Flexible authentication. Likewise, ports that are enabled for Flexible authentication cannot be added manually to the auth-default VLAN. - Enter the
mac-authentication enable{ all | ethernet stack/slot/port } command to enable MAC authentication on all interfaces or a specific interface. - (Optional) Enter the
mac-authentication password-formatcommand to configure the format in which the MAC address is sent to the RADIUS server for authentication.By default, the MAC address is sent to the RADIUS server in lowercase in the xxxxxxxxxxxx format. As an option, you can change the address to uppercase. You can specify one of the following formats: - (Optional) Enter the
mac-authentication password-overridecommand to specify a user-defined password instead of the MAC address for MAC authentication.Note: The password can contain up to 32 alphanumeric characters but must not include blank spaces. - (Optional) Enter the
mac-authentication dot1x-disablecommand to configure the device not to perform 802.1X authentication after MAC authentication when MAC authentication succeeds for the client. This is enabled by default, unless overruled by the RADIUS server through a dot1x-enable attribute. - (Optional) Enter the
mac-authentication dot1x-overridecommand to configure the device to perform 802.1X authentication after MAC authentication, if MAC authentication fails for the client.Note: This command is applicable only when the authentication sequence is configured as MAC authentication followed by 802.1X authentication.