Rev.A0
1-May-11
149
8.
If user ID and password is correct, the authentication server will
send a Radius-Access-Accept to the authenticator. If not correct,
the authentication server will send a Radius-Access-Reject.
9.
When the authenticator PAE receives a Radius-Access-Accept, it
will send an EAP-Success to the supplicant. At this time, the
supplicant is authorized and the port connected to the supplicant
and under 802.1X control is in the authorized state. The supplicant
and other devices connected to this port can access the network. If
the authenticator receives a Radius-Access-Reject, it will send an
EAP-Failure to the supplicant. This means the supplicant is failed to
authenticate. The port it connected is in the unauthorized state, the
supplicant and the devices connected to this port won’t be allowed
to access the network.
10. When the supplicant issue an EAP-Logoff message to
Authentication server, the port you are using is set to be
unauthorized.
Fig. 3-55
Only MultiHost 802.1X is the type of authentication supported in the switch.
In this mode, for the devices connected to this port, once a supplicant is authorized,
the devices connected to this port can access the network resource through this
port.
802.1X Port-based Network Access Control function supported by the switch
is little bit complex, for it just support basic Multihost mode, which can distinguish
the device’s MAC address and its VID. The following table is the summary of the
combination of the authentication status and the port status versus the status of port
mode, set in 802.1X Port mode, port control state, set in 802.1X port setting. Here
Entry Authorized means MAC entry is authorized.
Access allowed
PC
LAN
Bridge
Radius Server
Access blocked
Port connect
Radius-Access-Challenge
Radius-Access-Accept
Radius-Access-Request
Radius-Access-Request
EAPOL-Start
EAP-Response/Identity
EAP-Response (cred)
EAP-Request/Identity
EAP-Request
EAP-Success
EAP-Failure
EAPOL EAP
Authenticator
Radius
EAP-Logoff
Summary of Contents for SM8T2DPA
Page 2: ......
Page 7: ...Rev A0 1 May 11 v Revision History Date Revision 05 01 2010 A0...
Page 90: ...Rev A0 1 Mar 11 88 Fig 3 36 Fig 3 37 Fig 3 38...
Page 91: ...Rev A0 1 May 11 89 Fig 3 39 Fig 3 40 Fig 3 41 Fig 3 42...
Page 104: ...Rev A0 1 Mar 11 102 Fig 3 61 Set up VLAN Tag Priority Mapping...
Page 105: ...Rev A0 1 May 11 103 Fig 3 62 Set up VLAN Tag Priority Mapping Finish...
Page 113: ...Rev A0 1 May 11 111 Fig 3 69 Frame Type Fig 3 70...
Page 114: ...Rev A0 1 Mar 11 112 Fig 3 71 Fig 3 72 Fig 3 73 ARP...
Page 115: ...Rev A0 1 May 11 113 Fig 3 74 ARP Fig 3 75 ARP Fig 3 76 ARP Fig 3 77 ARP...
Page 116: ...Rev A0 1 Mar 11 114 Fig 3 79 ARP Fig 3 80 ARP Fig 3 81 ARP...
Page 117: ...Rev A0 1 May 11 115 Fig 3 82 ARP Fig 3 83 ARP Fig 3 84 ARP Fig 3 85 ARP Fig 3 86 ARP...
Page 118: ...Rev A0 1 Mar 11 116 Fig 3 87 ARP Fig 3 88 IPv4...
Page 119: ...Rev A0 1 May 11 117 Fig 3 89 IPv4 Fig 3 90 IPv4 Fig 3 91 IPv4 Fig 3 92 IPv4 Fig 3 93 IPv4...
Page 120: ...Rev A0 1 Mar 11 118 Fig 3 94 IPv4 Fig 3 95 IPv4 Fig 3 96 IPv4 Fig 3 97 IPv4 Fig 3 98 IPv4...
Page 121: ...Rev A0 1 May 11 119 Fig 3 99 IPv4 Fig 3 100 IPv4 Fig 3 101 IPv4 Fig 3 102 IPv4...
Page 122: ...Rev A0 1 Mar 11 120 Fig 3 103 IPv4 Fig 3 104 IPv4 Fig 3 105 IPv4...
Page 123: ...Rev A0 1 May 11 121 Fig 3 106 IPv4 Fig 3 107 IPv4 Fig 3 108 IPv4...
Page 124: ...Rev A0 1 Mar 11 122 Fig 3 109 IPv4 Fig 3 110 IPv4 Fig 3 111 IPv4...
Page 125: ...Rev A0 1 May 11 123 Fig 3 112 IPv4 Fig 3 113 IPv4 Fig 3 114 IPv4...
Page 126: ...Rev A0 1 Mar 11 124 Fig 3 115 IPv4 Fig 3 116 IPv4 Fig 3 117 IPv4...
Page 127: ...Rev A0 1 May 11 125 Fig 3 118 Action Fig 3 119 Rate Limiter...
Page 128: ...Rev A0 1 Mar 11 126 Fig 3 120 Port Copy Fig 3 121 DMAC Filter...
Page 129: ...Rev A0 1 May 11 127 Fig 3 122 VLAN ID Filter Fig 3 123 VLAN ID Filter Fig 3 124 Tag Priority...
Page 218: ...Rev A0 1 Mar 11 216 Fig 4 1...
Page 321: ...10900 Red Circle Drive Minnetonka MN 55344 Tel 1 952 941 7600 techsupport transition com...