![Nortel 2526T Configuration Download Page 31](http://html1.mh-extra.com/html/nortel/2526t/2526t_configuration_1707291031.webp)
Advanced EAPOL features
31
Support for non-EAPOL hosts on EAPOL-enabled ports is primarily
intended to accommodate printers and other dumb devices sharing a hub
with EAPOL clients.
Support for non-EAPOL hosts on EAPOL-enabled ports includes the
following features:
•
EAPOL and authenticated non-EAPOL clients are allowed on the port at
the same time. Authenticated non-EAPOL clients are hosts that satisfy
one of the following criteria:
— Host MAC address matches an entry in an allowed list preconfigured
for the port.
— Host MAC address is authenticated by RADIUS.
•
Non-EAPOL hosts are allowed even if no authenticated EAPOL hosts
exist on the port.
•
When a new host is seen on the port, non-EAPOL authentication is
performed as follows:
— If the MAC address matches an entry in the preconfigured allowed
MAC list, the host is allowed.
— If the MAC address does not match an entry in the preconfigured
allowed MAC list, the switch generates a <username, password> pair,
which it forwards to the network RADIUS server for authentication.
For more information about the generated credentials, see
"Non-EAPOL MAC RADIUS authentication" (page 32)
.
If the MAC address is authenticated by RADIUS, the host is allowed.
— If the MAC address does not match an entry in the preconfigured
allowed MAC list and also fails RADIUS authentication, the host is
counted as an intruder. Data packets from that MAC address are
dropped.
EAPOL authentication is not affected.
•
For RADIUS-authenticated non-EAPOL hosts, VLAN information from
RADIUS is ignored. Upon successful authentication, untagged traffic is
put in a VLAN preconfigured for the port.
•
For RADIUS-authenticated non-EAPOL hosts, VLAN information from
RADIUS is ignored. Upon successful authentication, untagged traffic
follows the PVID of the port.
•
Non-EAPOL hosts continue to be allowed on the port until the maximum
number of non-EAPOL hosts is reached. The maximum number of
non-EAPOL hosts allowed is configurable.
•
After the maximum number of allowed non-EAPOL hosts is reached, any
data packets received from additional non-EAPOL hosts are dropped.
Nortel Ethernet Routing Switch 2500 Series
Security — Configuration and Management
NN47215-505 (323165-B)
02.01
Standard
4.1
19 November 2007
Copyright © 2007, Nortel Networks
.
Summary of Contents for 2526T
Page 227: ......