![Cisco 350XG series Скачать руководство пользователя страница 473](http://html.mh-extra.com/html/cisco/350xg-series/350xg-series_administration-manual_67491473.webp)
Security: 802.1X Authentication
Port Authentication
Cisco 350XG & 550XG Series 10G Stackable Managed Switches
457
20
Port Authentication
The Port Authentication page enables configuration of parameters for each port.
Since some of the configuration changes are only possible while the port is in
Force Authorized state, such as host authentication, it is recommended that you
change the port control to Force Authorized before making changes. When the
configuration is complete, return the port control to its previous state.
NOTE
A port with 802.1x defined on it cannot become a member of a LAG.
To define 802.1X authentication:
STEP 1
Click
Security
> 802.1X/MAC/Web Authentication>
Port Authentication
.
This page displays authentication settings for all ports.
STEP 2
Select a port (Including the OOB port), and click
Edit.
STEP 3
Enter the parameters.
•
Interface
—Select a port (including the OOB port).
•
Current Port Control
—Displays the current port authorization state. If the
state is
Authorized
, the port is either authenticated or the
Administrative
Port Control
is
Force Authorized
. Conversely, if the state is
Unauthorized
,
then the port is either not authenticated or the
Administrative Port Control
is
Force Unauthorized
.
•
Administrative Port Control
—Select the Administrative Port Authorization
state. The options are:
-
Force Unauthorized
—Denies the interface access by moving the
interface into the unauthorized state. The device does not provide
authentication services to the client through the interface.
-
Auto
—Enables port-based authentication and authorization on the
device. The interface moves between an authorized or unauthorized
state based on the authentication exchange between the device and the
client.
-
Force Authorized
—Authorizes the interface without authentication.
•
RADIUS VLAN Assignment
—Select to enable Dynamic VLAN assignment
on the selected port.
-
Disable
—Feature is not enabled.