
© Copyright 2020 TRENDnet. All Rights Reserved.
TRE
NDnet User’s Guid
e
TPE-3012LS / TPE-3018LS
103
Security
This chapter contains information about the Port-based security features and the
procedures for setting this feature.
Configure RADIUS settings
Security > RADIUS
This section contains information and configuration procedures for the
Port-based Access Control. Port-based Network Access Control (IEEE 802.1x) is used to
control who can send traffic through and receive traffic from a switch port. With this
feature, the switch does not allow an end node to send or receive traffic through a port
until the user of the node logs on by entering a user name and password.
This feature can prevent an unauthorized individual from connecting a computer to a
port or using an unattended workstation to access your network resources. Only those
users to whom you have assigned a user name and password are able to use the switch
to access the network.
This feature can be used with one of two authentication methods:
•
The RADIUS authentication protocol requires that a remote RADIUS server is
present on your network. The RADIUS server performs the authentication of
the user name and password combinations.
•
The Dial-in User (local) authentication method allows you to set up the
authentication parameters internally in the switch without an external server.
In this case, the user name and password combinations are entered in the
associated with an optional VLAN when they are defined. Based on these
entries, the authentication process is done locally by the Web Management
Utility using a standard EAPOL transaction.
Note:
RADIUS with Extensible Authentication Protocol (EAP) extensions is the only
supported authentication server for this feature.
1. Log into your switch management page (see
Access your switch management page
on page 11).
2. Click on
Security
and click on
RADIUS
.
3. Review the settings. Click
Apply
to save the settings.
Configure the following parameters as required:
•
Retry:
Set the number of retries to authorize RADIUS servers.
•
Timeout:
Set the timeout period in seconds before starting the retry process
again for authorization of RADIUS servers.
•
Key String:
Set the RADIUS shared secret for all RADIUS servers.
To add a RADIUS server, click
Add
.
•
Address Type
–
Select the address type to identify the RADIUS server on the
network.
Hostname
,
IPv4,
or
IPv6
•
Server Address
–
Depending on the address type selected in the previous,
enter the Hostname, IPv4 address, or IPv6 address in the field provided to
identify the RADIUS server.
•
Server Port
–
Enter the RADIUS server port. By default, the RADIUS server port
is set to 1812.
•
Priority
–
Enter the RADIUS server priority value. The lower the number, the
higher the priority value. This can apply if you have multiple RADIUS servers
listed and which will indicate which RADIUS servers to take priority over others
in the list.
•
Key String
–
By default, the Use Default setting is checked to use the Default
Key String/Shared Secret specified in the global settings. If the key
string/shared secret for a specified RADIUS server, uncheck the Use Default
option and enter the key string/shared secret in the field provided.
•
Retry
–
By default, the Use Default setting is checked to use the Retry number
specified in the global settings. If the Retry number for a specified RADIUS
server, uncheck the Use Default option and enter the Retry number in the field
provided.
Summary of Contents for TPE-3012LS
Page 1: ...TRENDnet User s Guide Cover Page...
Page 187: ......