84
C
HAPTER
10: M
AKING
Y
OUR
N
ETWORK
S
ECURE
■
Before you enable Network Login or Rada you must ensure that:
■
RADIUS has been configured on the Switch.
■
The RADIUS server in your network is operational.
■
If the RADIUS server fails or is unavailable, client devices will be unable
to access the network or be restricted to the default access.
■
Network Login and Rada are not supported on ports configured to
operate as members of an aggregated link.
■
Some client devices that are connected to the Switch port may not
support network login, for example printers. You should configure the
Switch port to operate in Automatic Learning mode, so that network
traffic that does not match the MAC address for the client device is
filtered, or use the basic Rada mode.
■
You should enable Network Login or Rada on all relevant Switch ports.
Failure to enable authentication on a single port could compromise
the security of the entire network.
RADIUS Server settings for Auto VLAN
When setting up Auto VLAN on a RADIUS server the following attributes
must be set to supply VLAN data to the Switch:
Table 8
Setting Auto VLAN attributes
The Tunnel-Private-Group-ID attribute specifies the VLAN to be assigned.
This can take various forms to indicate if the port is untagged or tagged
member, for example ‘2u 3t' means that the port is an untagged member
of VLAN 2 and a tagged member of VLAN 3.
The switch will assign the first VLAN number with no suffix, or with a ‘U’
or ‘u’ suffix, as an untagged VLAN for the port. Any further VLAN
numbers with no suffix, or with the ‘U’ or ‘u’ suffix, will be assigned as a
tagged VLAN on the same port. For example; all the following strings are
identical after processing: “23 7T 88T”, “7T 88t 23u”, “88T 23 7t “,
”23 7 88”, “7T 23u 88u”.
Attribute
Value
Tunnel-Type
VLAN
Tunnel-Medium-Type
802
Tunnel-Private-Group-ID
<VLAN ID to be assigned>
dua1730-0bAA03.book Page 84 Monday, July 11, 2005 11:14 AM
Содержание 3C17300-US - SuperStack 3 Switch 4226T
Страница 7: ...D STANDARDS SUPPORTED GLOSSARY INDEX dua1730 0bAA03 book Page 7 Monday July 11 2005 11 14 AM ...
Страница 8: ...dua1730 0bAA03 book Page 8 Monday July 11 2005 11 14 AM ...
Страница 14: ...14 dua1730 0bAA03 book Page 14 Monday July 11 2005 11 14 AM ...
Страница 22: ...22 CHAPTER 1 SWITCH FEATURES OVERVIEW dua1730 0bAA03 book Page 22 Monday July 11 2005 11 14 AM ...
Страница 38: ...38 CHAPTER 3 USING MULTICAST FILTERING dua1730 0bAA03 book Page 38 Monday July 11 2005 11 14 AM ...
Страница 47: ...How STP Works 47 Figure 11 STP configurations dua1730 0bAA03 book Page 47 Monday July 11 2005 11 14 AM ...
Страница 64: ...64 CHAPTER 7 STATUS MONITORING AND STATISTICS dua1730 0bAA03 book Page 64 Monday July 11 2005 11 14 AM ...
Страница 86: ...86 CHAPTER 10 MAKING YOUR NETWORK SECURE dua1730 0bAA03 book Page 86 Monday July 11 2005 11 14 AM ...
Страница 92: ...92 dua1730 0bAA03 book Page 92 Monday July 11 2005 11 14 AM ...
Страница 96: ...96 APPENDIX A CONFIGURATION RULES dua1730 0bAA03 book Page 96 Monday July 11 2005 11 14 AM ...
Страница 100: ...100 APPENDIX B NETWORK CONFIGURATION EXAMPLES dua1730 0bAA03 book Page 100 Monday July 11 2005 11 14 AM ...
Страница 108: ...108 APPENDIX D STANDARDS SUPPORTED dua1730 0bAA03 book Page 108 Monday July 11 2005 11 14 AM ...
Страница 122: ...122 INDEX dua1730 0bAA03 book Page 122 Monday July 11 2005 11 14 AM ...