![Dell PowerConnect 7024 Manual Download Page 510](http://html.mh-extra.com/html/dell/powerconnect-7024/powerconnect-7024_manual_86095510.webp)
510
Configuring 802.1X and Port-Based Security
Dynamic VLAN Creation
If RADIUS-assigned VLANs are enabled thought the Authorization Network
RADIUS configuration option, the RADIUS server is expected to include the
VLAN ID in the 802.1X tunnel attributes of its response message to the
switch. If dynamic VLAN creation is enabled on the switch and the RADIUS-
assigned VLAN does not exist, then the assigned VLAN is dynamically
created. This implies that the client can connect from any port and can get
assigned to the appropriate VLAN. This gives flexibility for clients to move
around the network without much additional configuration required.
Guest VLAN
The Guest VLAN feature allows a switch to provide a distinguished service to
unauthenticated users. This feature provides a mechanism to allow users
access to hosts on the guest vlan. For example, a company might provide a
guest VLAN to visitors and contractors to permit network access that allows
visitors to connect to external network resources, such as the Internet, with
no ability to browse information on the internal LAN.
In port-based 802.1X mode, when a client that does not support 802.1X is
connected to an unauthorized port that is 802.1X-enabled, the client does not
respond to the 802.1X requests from the switch. Therefore, the port remains
in the unauthorized state, and the client is not granted access to the network.
If a guest VLAN is configured for that port, then the port is placed in the
configured guest VLAN and the port is moved to the authorized state,
allowing access to the client. However, if the port is in MAC-based 802.1X
authentication mode, it will not move to the authorized state. MAC-based
mode makes it possible for both authenticated and guest clients to use the
same port at the same time.
Client devices that are 802.1X-supplicant-enabled authenticate with the
switch when they are plugged into the 802.1X-enabled switch port. The
switch verifies the credentials of the client by communicating with an
authentication server. If the credentials are verified, the authentication server
informs the switch to
unblock
the switch port and allows the client
unrestricted access to the network; i.e., the client is a member of an internal
VLAN.
Guest VLAN Supplicant mode can be configured on a per-port basis. If a
client does not attempt authentication on a port, and the port is configured
for Guest VLAN, the client is assigned to the Guest VLAN configured on that
Summary of Contents for PowerConnect 7024
Page 134: ...134 Setting Basic Network Information ...
Page 290: ...290 Managing General System Settings Figure 11 14 SNTP Servers Table ...
Page 348: ...348 Configuring SNMP ...
Page 430: ...430 Monitoring Switch Traffic ...
Page 444: ...444 Configuring iSCSI Optimization ...
Page 538: ...538 Configuring 802 1X and Port Based Security ...
Page 594: ...594 Configuring VLANs Figure 21 16 GVRP Port Parameters Table ...
Page 600: ...600 Configuring VLANs Figure 21 23 Double VLAN Port Parameter Table ...
Page 658: ...658 Configuring the Spanning Tree Protocol ...
Page 693: ...Configuring Port Based Traffic Control 693 Figure 24 3 Storm Control 5 Click Apply ...
Page 780: ...780 Configuring Connectivity Fault Management ...
Page 804: ...804 Snooping and Inspecting Traffic Figure 27 17 DAI Interface Configuration Summary ...
Page 818: ...818 Snooping and Inspecting Traffic ...
Page 836: ...836 Configuring Link Aggregation ...
Page 882: ...882 Configuring DHCP Server Settings ...
Page 916: ...916 Configuring L2 and L3 Relay Features Figure 33 3 DHCP Relay Interface Summary ...
Page 924: ...924 Configuring L2 and L3 Relay Features Figure 33 12 IP Helper Statistics ...
Page 930: ...930 Configuring L2 and L3 Relay Features ...
Page 1004: ...1004 Configuring OSPF and OSPFv3 ...
Page 1044: ...1044 Configuring VRRP ...
Page 1057: ...Configuring IPv6 Routing 1057 Figure 37 9 IPv6 Route Preferences ...
Page 1064: ...1064 Configuring IPv6 Routing ...
Page 1084: ...1084 Configuring DHCPv6 Server and Relay Settings ...
Page 1091: ...Configuring Differentiated Services 1091 Figure 39 5 DiffServ Class Criteria ...
Page 1114: ...1114 Configuring Differentiated Services ...
Page 1130: ...1130 Configuring Class of Service ...
Page 1136: ...1136 Configuring Auto VoIP ...
Page 1216: ...1216 Managing IPv4 and IPv6 Multicast ...