AT-S80 Management Software User’s Guide
Section I: Using the Menus Interface
189
As mentioned earlier, the switch itself does not authenticate the user
names and passwords from the clients. That is the responsibility of the
authentication server, which contains the RADIUS server software.
Instead, a switch acts as an intermediary for the authentication server by
denying access to the network by the client until the client has provided a
valid username and password, which the authentication server validates.
General Steps
Following are the general steps to implementing 802.1x Port-based
Network Access Control:
1. You must install RADIUS server software on one or more of your
network servers or management stations. Authentication protocol
server software is not available from Allied Telesis. Consult the
vendor’s documentation for server installation instructions.
2. You need to install 802.1x client software on those workstations that
are to be supplicants. Microsoft WinXP client software and Meeting
House Aegis client software have been verified as fully compatible with
the AT-S80 management software.
3. You must configure and activate the RADIUS client software in the
AT-S80 management software. The default setting for the
authentication protocol is disabled. You will need to provide the
following information:
The IP address of a RADIUS servers.
The encryption key used by the authentication server.
For instructions, refer to Chapter 18, “RADIUS Authentication Protocol”
on page 201.
4. You must configure the authenticator port settings, as explained in
“Configuring 802.1x Port-based Network Access Control Feature” on
page 193 in this chapter.
Port-based
Network Access
Control
Guidelines
Following are the guidelines for using this feature:
Ports set to Auto do not support port trunking or dynamic MAC address
learning.
The appropriate setting for a port on an AT-FS750/16 or AT-FS750/24
switch connected to an authentication server is Force-authorized, the
default setting. This is because an authentication server cannot
authenticate itself.
The authentication server must be a member of the Default VLAN by
communicating with the switch through a port that is an untagged
member of the Default VLAN.
Allied Telesis does not support connecting more than one supplicant to
an authenticator port on the switch. The switch allows only one
supplicant to log on per port.
Summary of Contents for AT-S80
Page 8: ...Contents 8 Appendix A AT S80 Software Default Settings 339 Index 343...
Page 12: ...Tables 12...
Page 24: ...24 Section I Using the Menus Interface...
Page 30: ...Chapter 2 Getting Started with the Menus Interface 30 Section I Using the Menus Interface...
Page 60: ...Chapter 4 Port Configuration 60 Section I Using the Menus Interface...
Page 78: ...Chapter 6 IGMP Snooping 78 Section I Using the Menus Interface...
Page 84: ...Chapter 7 Static Multicast Address 84 Section I Using the Menus Interface...
Page 90: ...Chapter 8 Port Mirroring 90 Section I Using the Menus Interface...
Page 96: ...Chapter 9 Dial in User Configuration 96 Section I Using the Menus Interface...
Page 118: ...Chapter 10 Virtual LANs 118 Section I Using the Menus Interface...
Page 170: ...Chapter 13 Rapid Spanning Tree Protocol RSTP 170 Section II Menus Interface...
Page 176: ...Chapter 14 Bandwidth Control 176 Section I Using the Menus Interface...
Page 206: ...Chapter 18 RADIUS Authentication Protocol 206 Section I Using the Menus Interface...
Page 212: ...212 Section II Using the Web Browser Interface...
Page 250: ...Chapter 23 Port Trunking 250 Section II Using the Web Browser Interface...
Page 254: ...Chapter 24 Port Mirroring 254 Section II Using the Web Browser Interface...
Page 260: ...Chapter 25 Static Multicast Address Table 260 Section II Using the Web Browser Interface...
Page 264: ...Chapter 26 IGMP Snooping 264 Section II Using the Web Browser Interface...
Page 272: ...Chapter 28 Bandwidth Control 272 Section II Using the Web Browser Interface...
Page 284: ...Chapter 29 Virtual LANs 284 Section II Using the Web Browser Interface...
Page 328: ...Chapter 36 Management Software Updates 328 Section II Using the Web Browser Interface...
Page 342: ...Appendix A AT S80 Software Default Settings 342...
Page 346: ...Index 346...