Hi@ster
Because mac authentication is performed on the core switch, the management IP address of the downstream switch cannot pass the mac authentication of the core device. The downstream switch is forwarded as a Layer 2 so that the business data below can be forwarded to the core normally, and the service is not affected, but unable to ping or connect to the switch under telnet.
Authentication is enabled under the physical port. All downstream terminals and devices must pass authentication before they can access it. You can configure the free-rule to release the management IP address of the downstream switch.
Configuration:
free-rule-template name portal_free_rule
free-rule 1 destination ip 10.xx.xxx.101 mask 255.255.255.255
If you have any problems, please post them in our Community. We are happy to solve them for you!