AS Series User Manual
94
Doc No.: AS5-0116-01
standard, but features many of the same characteristics as does port-based
802.1X. In Single 802.1X, at most one supplicant can get authenticated on the
port at a time. Normal EAPOL frames are used in the communication between
the supplicant and the switch. If more than one supplicant is connected to a
port, the one that comes first when the port's link comes up will be the first
one considered. If that supplicant doesn't provide valid credentials within a
certain amount of time, another supplicant will get a chance. Once a
supplicant is successfully authenticated, only that supplicant will be allowed
access. This is the most secure of all the supported modes. In this mode, the
Port Security module is used to secure a supplicant's MAC address once
successfully authenticated.
Multi 802.1X
In port-based 802.1X authentication, once a supplicant is successfully
authenticated on a port, the whole port is opened for network traffic. This
allows other clients connected to the port (for instance through a hub) to
piggy-back on the successfully authenticated client and get network access
even though they really aren't authenticated. To overcome this security
breach, use the Multi 802.1X variant.
Multi 802.1X is really not an IEEE standard, but features many of the same
characteristics as does port-based 802.1X. Multi 802.1X is - like Single 802.1X -
not an IEEE standard, but a variant that features many of the same
characteristics. In Multi 802.1X, one or more supplicants can get authenticated
on the same port at the same time. Each supplicant is authenticated
individually and secured in the MAC table using the Port Security module.
In Multi 802.1X it is not possible to use the multicast BPDU MAC address as
destination MAC address for EAPOL frames sent from the switch towards the
supplicant, since that would cause all supplicants attached to the port to reply
to requests sent from the switch. Instead, the switch uses the supplicant's
MAC address, which is obtained from the first EAPOL Start or EAPOL Response
Identity frame sent by the supplicant. An exception to this is when no
supplicants are attached. In this case, the switch sends EAPOL Request Identity
frames using the BPDU multicast MAC address as destination - to wake up any
supplicants that might be on the port.
The maximum number of supplicants that can be attached to a port can be
limited using the Port Security Limit Control functionality.
MAC-based Auth
Unlike port-based 802.1X, MAC-based authentication is not a standard, but
merely a best-practices method adopted by the industry. In MAC-based
authentication, users are called clients, and the switch acts as the supplicant
on behalf of clients. The initial frame (any kind of frame) sent by a client is
snooped by the switch, which in turn uses the client's MAC address as both
username and password in the subsequent EAP exchange with the RADIUS
Содержание AS5010-P
Страница 40: ...AS Series User Manual 39 Doc No AS5 0116 01 values...
Страница 69: ...AS Series User Manual 68 Doc No AS5 0116 01 values...
Страница 85: ...AS Series User Manual 84 Doc No AS5 0116 01 event...
Страница 103: ...AS Series User Manual 102 Doc No AS5 0116 01 values...
Страница 136: ...AS Series User Manual 135 Doc No AS5 0116 01 Example MSTI Configuration...
Страница 160: ...AS Series User Manual 159 Doc No AS5 0116 01...
Страница 175: ...AS Series User Manual 174 Doc No AS5 0116 01 Fig LLDP MED Configuration...
Страница 192: ...AS Series User Manual 191 Doc No AS5 0116 01 values...
Страница 199: ...AS Series User Manual 198 Doc No AS5 0116 01 member of all possible VLANs...
Страница 213: ...AS Series User Manual 212 Doc No AS5 0116 01 Fig The IP Voice VLAN Configuration...
Страница 224: ...AS Series User Manual 223 Doc No AS5 0116 01...
Страница 228: ...AS Series User Manual 227 Doc No AS5 0116 01 Fig The Port Tag Remarking...
Страница 237: ...AS Series User Manual 236 Doc No AS5 0116 01 Fig The DSCP Classification Configuration...
Страница 240: ...AS Series User Manual 239 Doc No AS5 0116 01 Fig The QoS Control List Configuration...
Страница 257: ...AS Series User Manual 256 Doc No AS5 0116 01 Fig The sFlow Configuration...
Страница 343: ...AS Series User Manual 342 Doc No AS5 0116 01 refresh occurs every 3 seconds Refresh Click to refresh the page...
Страница 401: ...AS Series User Manual 400 Doc No AS5 0116 01 default is 3...
Страница 403: ...AS Series User Manual 402 Doc No AS5 0116 01 No Click to undo any restart action...
Страница 415: ...AS Series User Manual 414 Doc No AS5 0116 01 Fig DMS Information Screen...
Страница 418: ...AS Series User Manual 417 Doc No AS5 0116 01 Version Device firmware version...
Страница 428: ...AS Series User Manual 427 Doc No AS5 0116 01 Fig the DMS Diagnostics Section...