
82
■ Each client that needs to be authenticated must have dot1x client software installed and
properly configured.
■ When using 802.1X authentication, the RADIUS server and 802.1X client must support
EAP. (The switch only supports EAPOL in order to pass the EAP packets from the server
to the client.)
■ The RADIUS server and client also have to support the same EAP authentication type -
MD5, PEAP, TLS, or TTLS. (Native support for these encryption methods is provided in
Windows 7, Windows Vista, Windows XP, and in Windows 2000 with Service Pack 4. To
support these encryption methods in Windows 95 and 98, you can use the AEGIS dot1x
client or other comparable client software.)
MAC-based authentication allows for authentication of more than one user on the same
port, and does not require the user to have special 802.1X software installed on his
system. The switch uses the client's MAC address to authenticate against the backend
server. However, note that intruders can create counterfeit MAC addresses, which makes
MAC-based authentication less secure than 802.1X authentication.
PATH
Configuration / Security / Network / NAS
Figure 31: Network Access Server Configuration
Summary of Contents for GEP-1070
Page 80: ...80 authentication from any point within the network...
Page 168: ...168...