Authentication Session Limits on an Interface

Flexible authentication allows multiple MAC addresses to be authenticated or denied on each interface.

By default, the number of MAC sessions that can be authenticated on a single interface is two. The maximum number of sessions can be changed using the authentication max-sessions command. The maximum number of authenticated MAC sessions on an interface depends on the ICX device and dynamic ACL assignments. If RADIUS assigns dynamic ACLs to at least one client on the interface, the maximum number of MAC sessions that can be authenticated is limited to 32 in all ICX devices.

If a dynamic ACL is not assigned to any of the clients on the interface, the maximum number of MAC addresses that can be authenticated varies depending on the ICX device as specified in the following table. System reload is not required for the changes to take effect. However, existing sessions on the interface are cleared for the changes to take effect.

Maximum Number of Authenticated MAC Sessions per Port by ICX Device

Supported Platforms Maximum Number of MAC Sessions per Port When None of the Clients Has Dynamic ACL Maximum Number of MAC Sessions per Port When at Least One Client Has Dynamic ACL
ICX 8200 1024 32
ICX 8100 1024 32
ICX 7850 1024 32
ICX 7650 1024 32
ICX 7550 1024 32
ICX 7150 1024 32
ICX 7150-ES Models 256 2

The system limit for authenticated MAC sessions also varies and depends on the ICX device and dynamic ACL assignments.

Maximum Number of Authenticated MAC Sessions per System (Standalone or Stack) by ICX Device

Supported Platforms Maximum Number of MAC Sessions per System When None of the Clients Has Dynamic ACL Maximum Number of MAC Sessions per System When at Least One Client Has Dynamic ACL
ICX 8200 1536 512
ICX 8100 1536 512
ICX 7850 1536 512
ICX 7650 1536 512
ICX 7550 1536 512
ICX 7150 1536 512
ICX 7150-ES Models 512 2

Note: Stacking is not supported on RUCKUS ICX 8100 devices.