INS_CWGE24MS_REV–
02/18/13 PAGE 77
INSTALLATION AND OPERATION MANUAL
CWGE24MS
TECH SUPPORT: 1.888.678.9427
Age Period
This setting applies to ports running MAC-based authentication, only.
Suppose a client is connected to a 3rd party switch or hub, which in turn
is connected to a port on this switch that runs MAC-based authentication,
and suppose the client gets successfully authenticated. Now assume that
the client powers down his PC. What should make the switch forget about
the authenticated client? Reauthentication will not solve this problem,
since this doesn’t require the client to be present, as discussed under
Reauthentication Enabled above. The solution is aging of authenticated
clients. The Age Period, which can be set to a number between 10 and
1000000 seconds, works like this: A timer is started when the client gets
authenticated. After half the age period, the switch starts looking for
frames sent by the client. If another half age period elapses and no frames
are seen, the client is considered removed from the system, and it will
have to authenticate again the next time a frame is seen from it. If, on
the other hand, the client transmits a frame before the second half of the
age period expires, the switch will consider the client alive, and leave it
authenticated. Therefore, an age period of T will require the client to send
frames more frequent than T/2 for him to stay authenticated.
Hold Time
This setting applies to ports running MAC-based authentication, only.
If the RADIUS server denies a client access, or a RADIUS server request
times out (according to the timeout specified on the Authentication
configuration page), the client is put on hold in the Unauthorized state.
In this state, frames from the client will not cause the switch to attempt to
reauthenticate the client. The Hold Time, which can be set to a number
between 10 and 1000000 seconds, determines the time after an EAP
Failure indication or RADIUS timeout that a client is not allowed access.
Port
The port number for which the configuration below applies.
Admin State
• Sets the authentication mode to one of the following options (only
used when 802.1X or MAC-based authentication is globally enabled):
Auto: Requires an 802.1X-aware client (supplicant) to be authorized
by the authentication server. Clients that are not 802.1X-aware will be
denied access.
• Authorized: Forces the port to grant access to all clients,
802.1X-aware or not. The switch transmits an EAPOL Success frame
when the port links up.
• Unauthorized: Forces the port to deny access to all clients,
802.1X-aware or not. The switch transmits an EAPOL Failure frame
when the port links up.
• MAC-Based: Enables MAC-based authentication on the port. The
switch doesn’t transmit or accept EAPOL frames on the port. Flooded
frames and broadcast traffic will be transmitted on the port, whether
or not clients are authenticated on the port, whereas unicast traffic
against an unsuccessfully authenticated client will be dropped. Clients
that are not (yet) successfully authenticated will not be allowed to
transmit frames of any kind.