Table 277: Port Access Control Port Configuration Fields
Field
Description
Interface
The interface with the settings to view or configure. If you have been redirected
to this page, this field is read-only and displays the interface that was selected
on the Port Access Control Port Summary page.
PAE Capabilities
The Port Access Entity (PAE) role, which is one of the following:
•
Authenticator – The port enforces authentication and passes authentication
information from a remote supplicant (client or host) to the authentication
server. If the server successfully authenticates the supplicant, the port allows
access.
•
Supplicant – The port is connected to an authenticator port and must be
granted permission by the authentication server before it can send and
receive traffic through the remote port.
To change the PAE capabilities of a port, click the
Edit
icon associated with the
field and select the desired setting from the menu in the Set PAE Capabilities
window.
Authenticator Options
The fields in this section can be changed only when the selected port is
configured as an authenticator port (that is, the PAE Capabilities field is set to
Authenticator).
Control Mode
The port-based access control mode on the port, which is one of the following:
•
Auto – The port is unauthorized until a successful authentication exchange
has taken place.
•
Force Unauthorized – The port ignores supplicant authentication attempts
and does not provide authentication services to the client.
•
Force Authorized – The port sends and receives normal traffic without client
port-based authentication.
•
MAC-Based – This mode allows multiple supplicants connected to the same
port to each authenticate individually. Each host connected to the port must
authenticate separately in order to gain access to the network. The hosts are
distinguished by their MAC addresses.
Quiet Period
The number of seconds that the port remains in the quiet state following a failed
authentication exchange.
Transmit Period
The value, in seconds, of the timer used by the authenticator state machine on
the port to determine when to send an EAPOL EAP Request/Identity frame to
the supplicant.
Guest VLAN ID
The value, in seconds, of the timer used for guest VLAN authentication.
Unauthenticated VLAN ID
The VLAN ID of the unauthenticated VLAN. Hosts that fail the authentication
might be denied access to the network or placed on a VLAN created for
unauthenticated clients. This VLAN might be configured with limited network
access. To set the unauthenticated VLAN ID, click the
Edit
icon associated with
the field and specify the ID value in the available field. To reset the
unauthenticated VLAN ID to the default value, click the Reset icon associated
with the field and confirm the action.
Supplicant Timeout
The amount of time that the port waits for a response before retransmitting an
EAP request frame to the client.
Server Timeout
The amount of time the port waits for a response from the authentication server.
Managing Device Security
ExtremeSwitching 200 Series: Administration Guide
276