Enabling MAC move

MAC move allows 802.1X or MAC authenticated users to move between ports on a device. For example, if an authenticated 802.1X user moves to another 802.1X-enabled port on the device, the authentication session is deleted from the first port. The user is reauthenticated on the new port.

If MAC move is disabled, 802.1X or MAC users authenticated on one port cannot pass authentication after they move to another port.

As a best practice, enable MAC move for users that roam between ports to access the network.

To enable MAC move:

Step

Command

Remarks

1. Enter system view.

system-view

N/A

2. Enable MAC move.

port-security mac-move permit

By default, MAC move is disabled.