配置了Windows NPS服务器作为用户MAC认证的Radius服务器,测试认证过程和功能正常。
不过用户担心NPS服务器出现问题会影响连接到这个交换机的所有设备,我们就在在接口上配置了mac-authentication re-authenticate server-unreachable keep-online,然后手动关闭NPS服务器测试,但是大约一个小时后,交换机下连的所有设备都下线了,直到我再启动NPS服务器才恢复正常。
这个是有什么问题呢?
===============================================================
===============display current-cOnfiguration===============
#
version 7.1.070, Release 6343P08
#
sysname xxxxxx
#
clock timezone HKT add 08:00:00
clock protocol ntp
#
irf mac-address persistent timer
irf auto-update enable
undo irf link-delay
irf member 1 priority 1
#
mac-authentication
mac-authentication domain mac-auth
mac-authentication user-name-format mac-address without-hyphen uppercase
mac-authentication authentication-method chap
#
lldp global enable
#
password-recovery enable
#
vlan 1
#
vlan 10
description Siemens
ip-subnet-vlan 0 ip 10.16.1.0 255.255.255.0
#
vlan 20
description Schneider
ip-subnet-vlan 0 ip 172.16.252.0 255.255.0.0
#
vlan 30
description Andover
ip-subnet-vlan 0 ip 192.168.11.0 255.255.255.0
#
vlan 40
description ALC TSSU Chiller
ip-subnet-vlan 0 ip 192.168.167.0 255.255.255.0
#
stp global enable
#
interface Bridge-Aggregation25
port link-type trunk
port trunk permit vlan 1 10 20 30 40
link-aggregation mode dynamic
#
interface NULL0
#
interface Vlan-interface1
ip address 192.168.1.17 255.255.255.0
#
interface Vlan-interface10
#
interface Vlan-interface20
#
interface Vlan-interface30
#
interface Vlan-interface40
#
interface GigabitEthernet1/0/1
port link-type hybrid
port hybrid vlan 1 10 20 30 40 untagged
port hybrid ip-subnet-vlan vlan 10
port hybrid ip-subnet-vlan vlan 20
port hybrid ip-subnet-vlan vlan 30
port hybrid ip-subnet-vlan vlan 40
mac-authentication
mac-authentication re-authenticate server-unreachable keep-online
undo mac-authentication offline-detect enable
#
(0)
最佳答案
接入接口有UP DOWN过么
# 在端口GigabitEthernet1/0/1上开启MAC地址重认证功能,并配置周期性重认证时间间隔为1800秒。
<Sysname> system-view
[Sysname] mac-authentication timer reauth-period 1800
[Sysname] interface gigabitethernet 1/0/1
[Sysname-GigabitEthernet1/0/1] mac-authentication re-authenticate
(0)
暂无评论
亲~登录后才可以操作哦!
确定你的邮箱还未认证,请认证邮箱或绑定手机后进行当前操作
举报
×
侵犯我的权益
×
侵犯了我企业的权益
×
抄袭了我的内容
×
原文链接或出处
诽谤我
×
对根叔社区有害的内容
×
不规范转载
×
举报说明
暂无评论