Security
Configuring 802.1X
265
Cisco Small Business 200 Series Smart Switch Administration Guide
17
Configuring 802.1X
Port-based access control has the effect of creating two types of access on the
device ports. One type of access enables uncontrolled communication,
regardless of the authorization state (
uncontrolled port
). The other type of access
authorizes communication between a host and the device.
The 802.1x is an IEEE standard for port-based network access control. The 802.1x
framework enables a device (the supplicant) to request port access from a remote
device (authenticator) to which it is connected. Only when the supplicant
requesting port access is authenticated and authorized is it permitted to send
data to the port. Otherwise, the authenticator discards the supplicant data .
Authentication of the supplicant is performed by an external RADIUS server
through the authenticator. The authenticator monitors the result of the
authentication.
In the 802.1x standard, a device can be a supplicant and an authenticator at a port
simultaneously, requesting port access and granting port access. However, this
device is only the authenticator, and does not take on the role of a supplicant.
The following varieties of 802.1X exist:
•
Single session 802.1X
:
-
Single-session/single host
—In this mode, the device, as an
authenticator, supports a single 802.1x session and grants permission to
use the port to the authorized supplicant. All access by other devices
received from the same port are denied until the authorized supplicant is
no longer using the port or the access is to the unauthenticated VLAN.
-
Single session/multiple hosts—This follows the 802.1x standard. In this
mode, the device as an authenticator allows any device to use a port as
long as it has been granted permission.
•
Multi-Session 802.1X
—Every device (supplicant) connecting to a port
must be authenticated and authorized by the device (authenticator)
separately in a different 802.1x session.
The device supports the 802.1x authentication mechanism, as described in the
standard, to authenticate and authorize 802.1x supplicants.
802.1X Parameters Workflow
Define the 802.1X parameters as follows:
Содержание Small Business 200
Страница 1: ...Cisco Small Business 200 Series Smart Switch Administration Guide Release 1 3 ADMINISTRATION GUIDE ...
Страница 13: ...Cisco Small Business 200 Series Smart Switch Administration Guide 13 Contents ...
Страница 24: ...Getting Started Window Navigation 11 Cisco Small Business 200 Series Smart Switch Administration Guide 1 ...
Страница 38: ...Status and Statistics Managing RMON 25 Cisco Small Business 200 Series Smart Switch Administration Guide 2 ...
Страница 124: ...Administration Discovery Configuring CDP 111 Cisco Small Business 200 Series Smart Switch Administration Guide 8 ...
Страница 144: ...Port Management Configuring Green Ethernet 131 Cisco Small Business 200 Series Smart Switch Administration Guide 9 ...
Страница 182: ...Port Management PoE Configuring PoE Settings 169 Cisco Small Business 200 Series Smart Switch Administration Guide 11 ...
Страница 206: ...VLAN Management Voice VLAN 193 Cisco Small Business 200 Series Smart Switch Administration Guide 12 ...
Страница 288: ...Security Denial of Service Prevention 275 Cisco Small Business 200 Series Smart Switch Administration Guide 17 ...