No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search


To have a better experience, please upgrade your IE browser.


S12700 V200R011C10 Configuration Guide - User Access and Authentication

This document describes the working mechanisms, configuration procedures, and configuration examples of User Access and Authentication features, such as AAA, DAA, NAC, PPPoE, Policy Association, and IP session.

Rate and give feedback:
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).
(Optional) Configuring the User Name Format

(Optional) Configuring the User Name Format


MAC address authentication uses the following user name formats:
  • MAC address: When the MAC address is used as the user name for MAC address authentication, the password can be the MAC address or a self-defined character string.
  • Fixed user name: Regardless of users' MAC addresses, all users have a fixed name and password specified by the administrator as an identity for authentication. Many users may be authenticated on the same interface. In this case, all users requiring MAC address authentication on the interface use the same fixed user name, and the server must only configure one user account to authenticate all users. This is applicable to a network environment with reliable access clients.
  • DHCP option: The device uses the DHCP option field specified by the user and a fixed password rather than the MAC address of the user as an identity for authentication.

If fixed user names are configured in the VLANIF interface view, Eth-Trunk interface view or port group view, the password must be set.

If a MAC address is configured as the user name in the port group view, the password cannot be set.

If configured in the system view, the user name format is valid for commands on all interfaces; if configured in the interface view, the user name format is valid for commands on this interface only. If configured in the interface view and system view at the same time, the user name format configured in the interface view has higher priority.


  1. Run system-view

    The system view is displayed.

  2. Configure the user name format in the system or interface view.
    1. Run interface interface-type interface-number

      The interface view is displayed; or configuration is directly performed in the system view.

    2. Run mac-authen username { fixed username [ password cipher password ] | macaddress [ format { with-hyphen [ normal ] | without-hyphen } [ uppercase ] [ password cipher password ] ] | dhcp-option option-code { circuit-id | remote-id } * [ separate separate ] [ format-hex ] password cipher password }

      The user name format is set for MAC address authentication.

      By default, a MAC address without hyphens (-) is used as the user name and password for MAC address authentication.


      When the user name format in MAC address authentication is configured, ensure that the authentication server supports this format.

Updated: 2019-10-21

Document ID: EDOC1000178117

Views: 131454

Downloads: 62

Average rating:
This Document Applies to these Products

Related Version

Related Documents

Previous Next