AT-S63 Management Software Menus User’s Guide
Section VIII: Port Security
577
specified in the initial authentication, regardless of the VLAN
assignments of subsequent authentications.
C - Control Direction
This parameter specifies how the port handles ingress and egress
broadcast and multicast packets when in the unauthorized state. When
a port is set to the authenticator role, it remains in the unauthorized
state until a client logs on by providing a username and password
combination. In the unauthorized state, the port only accepts EAP
packets from the client. All other ingress packets that the port might
receive from the client, including multicast and broadcast traffic, is
discarded until the supplicant has logged in. The options are:
Ingress
: A port, when in the unauthorized state, discards all
ingress broadcast and multicast packets from the client, but
forwards all egress broadcast and multicast traffic to the same
client.
Both
: A port, when in the unauthorized state, does not forward
ingress or egress broadcast and multicast packets from or to the
same client until the client logs in. This is the default.
Note
This parameter is only available when the authenticator’s mode is
set to Single. When set to Multiple, a port does not forward ingress
or egress broadcast or multicast packets until at least one client has
logged on.
D - Piggyback Mode
This parameter controls who can use the switch port in cases where
there are multiple clients using the port (e.g., the switch port is
connected to an Ethernet hub). If set to enabled, the port allows all
clients on the port to piggy-back onto the initial client’s authentication,
forwarding all packets after one client is authenticated. If set to
Disabled, the switch port forwards only those packets from the client
who is authenticated and discards packets from all other users.
Note
This parameter is only available when the authenticator’s mode is
set to Single.
E - Guest VLAN
This parameter specifies the name or VID of a Guest VLAN. The
authenticator port is a member of a Guest VLAN when no supplicant is
logged on. Clients do not log on to access a Guest VLAN. To remove a
Guest VLAN without assigning a new one, enter “none”.
7. Repeat this procedure starting with Step 4 to configure additional
authenticator ports on the switch.
Содержание AT-9400
Страница 16: ...Figures 16 ...
Страница 18: ...Tables 18 ...
Страница 28: ...Preface 28 ...
Страница 30: ...30 Section I Basic Operations ...
Страница 60: ...Chapter 1 Basic Switch Parameters 60 Section I Basic Operations ...
Страница 64: ...Chapter 2 Port Parameters 64 Section I Basic Operations Port Type The port type ...
Страница 84: ...Chapter 2 Port Parameters 84 Section I Basic Operations ...
Страница 124: ...Chapter 6 Static Port Trunks 124 Section I Basic Operations ...
Страница 144: ...144 Section II Advanced Operations ...
Страница 196: ...Chapter 10 File Downloads and Uploads 196 Section II Advanced Operations ...
Страница 218: ...Chapter 11 Event Logs and the Syslog Client 218 Section II Advanced Operations ...
Страница 242: ...Chapter 13 Access Control Lists 242 Section II Advanced Operations ...
Страница 294: ...294 Section III IGMP Snooping MLD Snooping and RRP Snooping ...
Страница 314: ...Chapter 19 MLD Snooping 314 Section III IGMP Snooping MLD Snooping and RRP Snooping ...
Страница 318: ...318 Section IV SNMPv3 ...
Страница 416: ...Chapter 21 SNMPv3 416 Section IV SNMPv3 ...
Страница 418: ...418 Section V Spanning Tree Protocols ...
Страница 470: ...470 Section VI Virtual LANs ...
Страница 478: ...Chapter 24 Port based and Tagged VLANs 478 Section VI Virtual LANs The new Sales VLAN has now been created ...
Страница 480: ...Chapter 24 Port based and Tagged VLANs 480 Section VI Virtual LANs The new Engineering VLAN has now been created ...
Страница 520: ...Chapter 26 Multiple VLAN Modes 520 Section VI Virtual LANs ...
Страница 532: ...Chapter 27 Protected Ports VLANs 532 Section VI Virtual LANs ...
Страница 546: ...546 Section VII Internet Protocol Routing ...
Страница 560: ...560 Section VIII Port Security ...
Страница 568: ...Chapter 30 MAC Address based Port Security 568 Section VIII Port Security ...
Страница 586: ...Chapter 31 802 1x Port based Network Access Control 586 Section VIII Port Security ...
Страница 588: ...588 Section IX Management Security ...
Страница 610: ...Chapter 33 Encryption Keys 610 Section IX Management Security ...
Страница 650: ...Chapter 36 TACACS and RADIUS Protocols 650 Section IX Management Security ...
Страница 660: ...Chapter 37 Management Access Control List 660 Section IX Management Security ...
Страница 668: ...Index 668 ...