
35
• Single 802.1X
• Multi 802.1X
• MAC-Based Auth.
If a client is denied access - either because the RADIUS server denies the
client access or becaus e the RADIUS server request times out (according to
the timeout specified in “AAA") - the client is put on hold in the Unauthorized
state. The hold timer does not count during an on -going authentication.
In MAC-based Auth. mode, the switch will ignore new frames coming from the
client during the hold time.
dot1x mode
command is used to eanble 802.1x function. And “
no dot1x
mode
” command is used to disable it.
dot1x radius_qos
command is used to globally enable RADIUS-server
assigning QoS Class functionalit
y. And “
no dot1x radius_qos
” command is
used to disable it. When enabled, the individual ports' ditto setting determine
whether RADIUS-assigned VLAN is enabled on that port. When disabled,
RADIUS-server assigned VLAN is disabled on all ports.
RADIUS-assigned QoS provides a means to centrally control the traffic class
to which traffic coming from a successfully authenticated supplicant is
assigned on the switch. The RADIUS server must be configured to transmit
special RADIUS attributes to take advantage of this feature.
dot1x radius_vlan
command is used to globally enable RADIUS-server
assigned VLAN functionality. And “
no dot1x radius_vlan
” is used to disable
it. When enabled, the individual ports' ditto setting determine whether
RADIUS-assigned VLAN is enabled on that port. When disabled, RADIUS-
server assigned VLAN is disabled on all ports.
RADIUS-assigned VLAN provides a means to centrally control the VLAN on
which a successfully authenticated supplicant is placed on the switch.
Incoming traffic will be classified to and switched on the RADIUS-assigned
VLAN. The RADIUS server must be configured to transmit special RADIUS
attributes to take advantage of this feature.
dot1x reauthentication
command is used to enable reauthentication function
of 802.1x func
tion. And “
no dot1x reauthentication
” command is used to
disable it.
If enabled, successfully authenticated supplicants/clients are reauthenticated
after the interval specified by the Reauthentication Period. Reauthentication for
802.1X-enabled ports can be used to detect if a new device is plugged into a
switch port or if a supplicant is no longer attached.
For MAC-based ports, reauthentication is only useful if the RADIUS server
configuration has changed. It does not involve communication between the
switch and the client, and therefore doesn't imply that a client is still present
on a port.
dot1x reauthperiod x
command is used to set the Reauthentication Period, in
seconds, after which a connected client must be reauthenticated. This is only
active if th
e Reauthentication is enabled. “
x
” is a number in the range 1 to
3600 seconds.
Содержание GSW-3208M1
Страница 1: ...1 GSW 3208M1 3216M1 3424M1 L2 Managed GbE Switches ...
Страница 176: ...173 ...
Страница 185: ...182 ...
Страница 202: ...199 This page is used to show the details of log Entering the ID details of the log will be shown ...
Страница 213: ...210 This page provides an overview of RMON Event table entries ...
Страница 215: ...212 This page provides an overview for LACP statistics for all ports ...
Страница 227: ...224 6 4 29 Monitor sFlow This page shows receiver and per port sFlow statistics ...
Страница 240: ......