54
Chapter 4
Web Configuration & Operation
4.6.2.2.1 Configuration
System Configuration
Mode:
Enable 802.1X and MAC-based authentication globally on the switch. If globally disabled, all ports are
allowed to forward frames.
Reauthentication Enabled:
Select the checkbox to set clients to be re-authenticated after an interval set in
"Reauthentication Period" field. Re-autentication can be used to detect if a new device is attached to a switch port.
Reauthentication Period:
Specify the time interval for a connected device to be re-authenticated. By default, the re-
authenticated period is set to 3600 seconds. The allowed range is 1
~
3600 seconds.
EAPOL Timeout:
Specify the time that the switch waits for a supplicant response during an authentication session before
transmitting a Request Identify EAPOL packet. By default, it is set to 30 seconds. The allowed range is 1
~
255 seconds.
Aging Period:
Specify the period that is used to age out a client’s allowed access to the switch via 802.1X and MAC-based
authentication. The default period is 300 seconds. The allowed range is 10
~
1000000 seconds.
Hold Time:
The time after an EAP Failure indication or RADIUS timeout that a client is not allowed access. This setting
applies to ports running Single 802.1X, Multi 802.1X, or MAC-based authentication. By default, hold time is set to 10
seconds. The allowed range is 10
~
1000000 seconds.
Radius-Assigned QoS Enabled:
Select the checkbox to globally enable RADIUS assigned QoS.
Radius-Assigned VLAN Enabled:
RADIUS-assigned VLAN provides a means to centrally control the VLAN on which a
successfully authenticated supplicant is placed on the switch. Incoming traffic will be classified to and switched on the
RADIUS-assigned VLAN. The RADIUS server must be configured to transmit special RADIUS attributes to take advantage of
this feature.
The "RADIUS-Assigned VLAN Enabled" checkbox provides a quick way to globally enable/disable RADIUS-server assigned
VLAN functionality. When checked, the individual ports' ditto setting determines whether RADIUS-assigned VLAN is
enabled on that port. When unchecked, RADIUS-server assigned VLAN is disabled on all ports.
Guest VLAN Enabled:
A Guest VLAN is a special VLAN typically with limited network access. When checked, the individual
ports' ditto setting determines whether the port can be moved into Guest VLAN. When unchecked, the ability to move to
Summary of Contents for GSW-3208M2
Page 1: ...1 GSW 3208M2 Managed Gigabit Ethernet Switch ...
Page 145: ......