DXS-3227, DXS-3227P, DXS-3250 and DXS-3250E EWS User Guide
Page 126
Network Security Overview
This section provides an overview of network security and contains the following topics:
•
Port-Based Authentication
•
Advanced Port-Based Authentication
Port-Based Authentication
Port-based authentication authenticates users on a per-port basis via an external server. Only authenticated and
approved system users can transmit and receive data. Ports are authenticated via a RADIUS server using the
Extensible Authentication Protocol
(EAP). Port-based authentication includes:
•
Authenticators
— Specifies the device port which is authenticated before permitting system access.
•
Supplicants
— Specifies the host connected to the authenticated port requesting to access the system ser-
vices.
•
Authentication Server
— Specifies the server that performs the authentication on behalf of the authentica-
tor, and indicates whether the supplicant is authorized to access system services.
Port-based authentication creates two access states:
•
Controlled Access
— Permits communication between the supplicant and the system, if the supplicant is
authorized.
•
Uncontrolled Access
— Permits uncontrolled communication regardless of the port state.
The device currently supports port-based authentication via RADIUS servers.
Advanced Port-Based Authentication
Advanced port-based authentication enables multiple hosts to be attached to a single port. Advanced port-based
authentication requires only one host to be authorized for all hosts to have system access. If the port is unautho-
rized, all attached hosts are denied access to the network.
Advanced port-based authentication also enables user-based authentication. Specific VLANs in the device are
always available, even if specific ports attached to the VLAN are unauthorized. For example, Voice over IP does
not require authentication, while data traffic requires authentication. VLANs for which authorization is not required
can be defined. Unauthenticated VLANs are available to users, even if the ports attached to the VLAN are defined
as authorized.
Advanced port-based authentication is implemented in the following modes:
•
Single Host Mode
— Allows port access only to the authorized host.
•
Multiple Host Mode
— Multiple hosts can be attached to a single port. Only one host must be authorized for
all hosts to access the network. If the host authentication fails, or an EAPOL-logoff message is received, all
attached clients are denied access to the network.
•
Guest VLANs
— Provides limited network access to authorized ports. If a port is denied network access via
port-based authorization, but the Guest VLAN is enabled, the port receives limited network access. For exam-
ple, a network administrator can use Guest VLANs to deny network access via port-based authentication, but
grant Internet access to unauthorized users.
•
Unauthenticated VLANS
— Are available to users, even if the ports attached to the VLAN are defined as
unauthorized.
Summary of Contents for DXS-3250E - xStack Switch
Page 327: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 326...
Page 397: ...Technical Support Contacting D Link Technical Support Page 395...
Page 398: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 396...
Page 399: ...Technical Support Contacting D Link Technical Support Page 397...
Page 400: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 398...
Page 401: ...Technical Support Contacting D Link Technical Support Page 399...
Page 402: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 400...
Page 403: ...Technical Support Contacting D Link Technical Support Page 401...
Page 404: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 402...
Page 405: ...Technical Support Contacting D Link Technical Support Page 403...
Page 406: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 404...
Page 407: ...Technical Support Contacting D Link Technical Support Page 405...
Page 408: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 406...
Page 409: ...Technical Support Contacting D Link Technical Support Page 407...
Page 410: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 408...
Page 411: ...Technical Support Contacting D Link Technical Support Page 409...
Page 412: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 410...
Page 413: ...Technical Support Contacting D Link Technical Support Page 411...
Page 414: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 412...
Page 415: ...Technical Support Contacting D Link Technical Support Page 413...
Page 416: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 414...
Page 417: ...Technical Support Contacting D Link Technical Support Page 415...
Page 418: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 416...
Page 419: ...Technical Support Contacting D Link Technical Support Page 417...
Page 420: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 418...
Page 421: ...Technical Support Contacting D Link Technical Support Page 419...
Page 422: ...DXS 3227 DXS 3227P DXS 3250 and DXS 3250E EWS User Guide Page 420...