INS_CWGE24MS2_REV–
10/05/16 PAGE 225
INSTALLATION AND OPERATION MANUAL
CWGE24MS2
TECH SUPPORT: 1.888.678.9427
When the client provides the login credentials, the Switch sends an authentication request to a
RADIUS server. The RADIUS server validates whether this client is allowed access to the port.
Local User Accounts
By storing user profiles locally on the Switch, your Switch is able to authenticate users without
interacting with a network authentication server. However, there is a limit on the number of users
you may authenticate in this way.
Guest VLAN
The Guest VLAN in IEEE 802.1x port authentication on the switch to provide limited services to
clients, such as downloading the IEEE 802.1x client. These clients might be upgrading their system
for IEEE 802.1x authentication.
When you enable a guest VLAN on an IEEE 802.1x port, the switch assigns clients
to a guest
VLAN when the switch does not receive a response to its EAP request/identity frame or when
EAPOL packets are not sent by the client.
Port Parameters
» Admin Control Direction:
both - drop incoming and outgoing packets on the port when a user has not passed 802.1x port
authentication.
in - drop only incoming packets on the port when a user has not passed 802.1x port
authentication.
» Re-authentication:
Specify if a subscriber has to periodically re-enter his or her username and password to stay
connected to the port.
» Reauth-period:
Specify how often a client has to re-enter his or her username and password to stay connected
to the port. The acceptable range for this field is 0 to 65535 seconds.
» Port Control Mode:
auto : Users can access network after authenticating.
force-authorized : Users can access network without authentication.
force-unauthorized : Users cannot access network.
» Quiet Period:
Specify a period of the time the client has to wait before the next re-authentication attempt. This
will prevent the Switch from becoming overloaded with continuous re-authentication attempts
from the client. The acceptable range for this field is 0 to 65535 seconds.
» Server Timeout:
The server-timeout value is used for timing out the Authentication Server.
» Supp-Timeout:
The supp-timeout value is the initialization value used for timing out a Supplicant.
» Max-req Time:
Specify the amount of times the Switch will try to connect to the authentication server before
determining the server is down. The acceptable range for this field is 1 to 10 times.