Operation Manual – Centralized MAC Address Authentication
Quidway S3100 Series Ethernet Switches
Chapter 1 Centralized MAC Address
Authentication Configuration
Huawei Technologies Proprietary
1-1
Chapter 1 Centralized MAC Address
Authentication Configuration
1.1 Centralized MAC Address Authentication Overview
Centralized MAC address authentication is port-/MAC address-based authentication
used to control user permissions to access a network. Centralized MAC address
authentication can be performed without client-side software. With this type of
authentication employed, a switch authenticates a user upon detecting the MAC
address of the user for the first time.
Centralized MAC address authentication can be implemented in the following two
modes:
z
MAC address mode, where user MAC servers as both user name and password.
z
Fixed mode, where user names and passwords are configured on the switch in
advance. In this case, a user uses the previously configured user name and
password to log into the switch.
As for S3100 series Ethernet switches, authentication can be performed locally or on a
RADIUS server.
1)
When a RADIUS server is used for authentication, the switch serves as a RADIUS
client. Authentication is carried out through the cooperation of switches and the
RADIUS server.
z
In MAC address mode, a switch sends user MAC addresses detected to the
RADIUS serve as both user names and passwords. The rest handling procedures
are the same as that of 802.1x.
z
In fixed mode, a switch sends the user name and password previously configured
for the user to be authenticated to the RADIUS server and inserts the MAC
address of the user in the calling-station-id field of the RADIUS packet. The rest
handling procedures are the same as that of 802.1x.
z
A host can access a network if it passes the authentication performed by the
DADIUS server.
2)
When authentications are performed locally, users are authenticated by switches.
In this case,
z
For MAC address mode, the MAC addresses configured to be both user names
and passwords need to be in the format of HH-HH-HH, for example,
00-e0-fc-00-01-01.
z
For fixed mode, configure the user names and passwords as that for fixed mode.
z
The service type of a local user needs to be configured as lan-access.