Chapter 76 Port Authentication
XGS2220 Series User’s Guide
525
76.5 Compound Authentication
Use this screen to allow network access for clients that:
• pass either IEEE 802.1x authentication OR MAC authentication, or
• pass both IEEE 802.1x authentication AND MAC authentication.
The authentication modes are:
• In IEEE 802.1x authentication, the Switch prompts the client for login information in the form of a user
name and password. When the client provides the login credentials, the Switch sends an
authentication request to a RADIUS server. The RADIUS server validates whether this client is allowed
access to the port. Use the
SECURITY
>
AAA
>
RADIUS Server Setup
screen to configure the RADIUS
server.
• In MAC authentication, the login credentials are based on the source MAC address of the client
connecting to a port on the Switch along with a password configured specifically for MAC
authentication on the Switch.
Click
SECURITY
>
Port Authentication
>
Compound Authentication Mode
to display the configuration
screen as shown.
Guest VLAN
A guest VLAN is a pre-configured VLAN on the Switch that allows non-authenticated users to
access limited network resources through the Switch. You must also enable IEEE 802.1x
authentication on the Switch and the associated ports. Enter the number that identifies the
guest VLAN.
Make sure this is a VLAN recognized in your network.
Host-mode
Specify how the Switch authenticates users when more than one user connect to the port
(using a hub).
Select
Multi-Host
to authenticate only the first user that connects to this port. If the first user
enters the correct credential, any other users are allowed to access the port without
authentication. If the first user fails to enter the correct credential, they are all put in the guest
VLAN. Once the first user who did authentication logs out or disconnects from the port, the rest
of the users are blocked until a user does the authentication process again.
Select
Multi-Secure
to authenticate each user that connects to this port.
Multi-secure Num If you set
Host-mode
to
Multi-Secure
, specify the maximum number of users (between 1 and
24) that the Switch will authenticate on this port.
Apply
Click
Apply
to save your changes to the Switch’s run-time memory. The Switch loses these
changes if it is turned off or loses power, so use the
Save
link on the top navigation panel to
save your changes to the non-volatile memory when you are done configuring.
Cancel
Click
Cancel
to begin configuring this screen afresh.
Table 305 SECURITY > Port Authentication > Guest VLAN (continued)
LABEL
DESCRIPTION