Chapter 12
| Security Measures
Configuring 802.1X Port Authentication
– 294 –
Configuring
Port Authenticator
Settings for 802.1X
Use the Security > Port Authentication (Configure Interface – Authenticator) page
to configure 802.1X port settings for the switch as the local authenticator. When
802.1X is enabled, you need to configure the parameters for the authentication
process that runs between the client and the switch (i.e., authenticator), as well as
the client identity lookup process that runs between the switch and authentication
server.
Command Usage
◆
When the switch functions as a local authenticator between supplicant devices
attached to the switch and the authentication server, configure the parameters
for the exchange of EAP messages between the authenticator and clients on
the Authenticator configuration page.
◆
This switch can be configured to serve as the authenticator on selected ports
by setting the Control Mode to Auto on this configuration page, and as a
supplicant on other ports by the setting the control mode to Force-Authorized
on this page and enabling the PAE supplicant on the Supplicant configuration
page.
Parameters
These parameters are displayed:
◆
Port
– Port number.
◆
Status
– Indicates if authentication is enabled or disabled on the port. The
status is disabled if the control mode is set to Force-Authorized.
◆
Authorized
– Displays the 802.1X authorization status of connected clients.
■
Yes
– Connected client is authorized.
■
N/A
– Connected client is not authorized, or port is not connected.
◆
Control Mode
– Sets the authentication mode to one of the following options:
■
Auto
– Requires a dot1x-aware client to be authorized by the
authentication server. Clients that are not dot1x-aware will be denied
access.
■
Force-Authorized
– Forces the port to grant access to all clients, either
dot1x-aware or otherwise. (This is the default setting.)
■
Force-Unauthorized
– Forces the port to deny access to all clients, either
dot1x-aware or otherwise.
◆
Operation Mode
– Allows single or multiple hosts (clients) to connect to an
802.1X-authorized port. (Default: Single-Host)
■
Single-Host
– Allows only a single host to connect to this port.
Summary of Contents for GEL-1061
Page 14: ...Contents 14...
Page 28: ...Section I Getting Started 28...
Page 38: ...Chapter 1 Introduction System Defaults 38...
Page 40: ...Section II Web Configuration 40...
Page 60: ...Chapter 2 Using the Web Interface Navigating the Web Browser Interface 60...
Page 164: ...Chapter 6 Address Table Settings Issuing MAC Address Traps 164...
Page 192: ...Chapter 8 Congestion Control Storm Control 192...
Page 204: ...Chapter 9 Class of Service Layer 3 4 Priority Settings 204...
Page 216: ...Chapter 10 Quality of Service Attaching a Policy Map to a Port 216...
Page 430: ...Chapter 14 Multicast Filtering MLD Snooping Snooping and Query for IPv4 430...
Page 436: ...Chapter 15 IP Tools Address Resolution Protocol 436...
Page 474: ...Section III Appendices 474...
Page 492: ...Glossary 492...
Page 500: ...E052016 ST R02 150200001416A...