Waters Network Systems
User’s Manual
Page 87
GSM-2116 and GSM-2124
Figure 5.55 – 802.1x Authentication
The type of authentication supported in the switch is multihost 802.1x. In this mode, once a
supplicant is authorized, the devices connected to this port can access the network resources.
802.1X Port-based Network Access Control function supported by the switch is complex.
Support, by basic multihost mode, can distinguish the device’s MAC address and its VID. The
following table summarizes the combination of the authentication status and the port status
versus the status of port mode, set in 802.1X Port mode, port control state, set in 802.1X port
setting. Entry Authorized means MAC entry is authorized.
Port Mode
Port Control
Authentication
Port Status
Disable
Don’t Care
Don’t Care
Port Uncontrolled
Multihost Auto
Successful Port
Authorized
Multihost Auto
Failure Port
Unauthorized
Multihost
ForceUnauthorized
Don’t Care
Port Unauthorized
Multihost ForceAuthorized Don’t
Care Port
Authorized
Table 5.3
Access allowed
PC
LAN
Bridge
Radius Server
Access blocked
Port connect
Radius-Access-Challenge
Radius-Access-Accept
Radius-Access-Request
Radius-Access-Request
EAPOL-Start
EAP-Response/Identity
EAP-Response (cred)
EAP-Request/Identity
EAP-Request
EAP-Success
EAP-Failure
EAPOL
EAP
Authenticator
Radius
EAP-Logoff