GS2210 Series User’s Guide
157
C
H A P T E R
1 8
Port Authentication
18.1 Port Authentication Overview
This chapt er descr ibes t he I EEE 802.1x and MAC aut hent icat ion m et hods.
Por t aut hent icat ion is a way t o validat e access t o por t s on t he Sw it ch t o client s based on an ext er nal
ser ver ( aut hent icat ion ser ver ) . The Sw it ch suppor t s t he follow ing m et hods for por t aut hent icat ion:
• I EEE 8 0 2 .1 x
2
- An aut hent icat ion ser ver validat es access t o a por t based on a user nam e and
passw ord provided by t he user.
• M AC Au t h e n t ica t ion - An aut hent icat ion ser ver validat es access t o a por t based on t he MAC
address and passwor d of t he client .
Bot h t y pes of aut hent icat ion use t he RADI US ( Rem ot e Aut hent icat ion Dial I n User Ser vice, RFC
2138, 2139) pr ot ocol t o validat e user s. See
infor m at ion on configur ing your RADI US ser ver set t ings.
Not e: I f you enable I EEE 802.1x aut hent icat ion and MAC aut hent icat ion on t he sam e
por t , t he Sw it ch per for m s I EEE 802.1x aut hent icat ion fir st . I f a user fails t o
aut hent icat e v ia t he I EEE 802.1x m et hod, t hen access t o t he por t is denied.
18.1.1 What You Can Do
•
Use t he Por t Au t h e n t ica t ion scr een (
) t o display t he links t o t he
configurat ion scr eens wher e you can enable t he por t aut hent icat ion m et hods.
•
Use t he 8 0 2 .1 x scr een (
) t o act ivat e I EEE 802.1x secur it y.
•
Use t he M AC Au t h e n t ica t ion scr een (
) t o act ivat e MAC aut hent icat ion.
18.1.2 What You Need to Know
IEEE 802.1x Authentication
The follow ing figur e illust rat es how a client connect ing t o a I EEE 802.1x aut hent icat ion enabled por t
goes t hr ough a validat ion pr ocess. The Sw it ch prom pt s t he client for login infor m at ion in t he for m of
a user nam e and passw or d. When t he client pr ovides t he login cr edent ials, t he Swit ch sends an
aut hent icat ion r equest t o a RADI US ser ver. The RADI US ser ver validat es w het her t his client is
allow ed access t o t he por t .
2.
At the time of writing, IEEE 802.1x is not supported by all operating systems. See your operating system documentation.
If your operating system does not support 802.1x, then you may need to install 802.1x client software.