Transition Networks
S4224 Web User Guide
33558 Rev. C
Page 94 of 669
NAS (Network Access Server) Configuration
Configuration > Security > Network > NAS
The
Configuration
>
Security
>
Network
>
NAS
menu path lets you configure the IEEE 802.1X and
MAC-based authentication system and port settings.
The IEEE 802.1X standard defines a port-based access control procedure that prevents unauthorized
access to a network by requiring users to first submit credentials for authentication. One or more central
servers, the backend servers, determine whether the user is allowed access to the network.
These backend (RADIUS) servers are configured from the
Configuration
>
Security
>
AAA
menu path.
The IEEE802.1X standard defines port-based operation, but non-standard variants overcome security
limitations as explained below.
MAC-based authentication allows for authentication of more than one user on the same port, and doesn't
require the user to have special 802.1X supplicant software installed on his system. A device uses the
user's MAC address to authenticate against the backend server. Intruders can create counterfeit MAC
addresses, which makes MAC-based authentication less secure than 802.1X authentication.
IEEE 802.1X Port-based Network Access Control provides a standard for authenticating and authorizing
devices attached to a LAN port. Generally, IEEE 802.1X is port-based; however, the S4224 also supports
MAC-based network access control.
The NAS configuration consists of two sections, for system-wide and port-wide NAS configuration.
The NAS page parameters are explained below.