5
802.1X
An authentication server must authenticate a client connected to an 802.1X switch port. Until the
authentication, only extensible authentication protocol over LAN (EAPOL) traffic is allowed through the
port to which a client is connected. After authentication is successful, normal traffic passes through the
port.
The Dell Networking operating software supports remote authentication dial-in service (RADIUS) and
active directory environments using 802.1X Port Authentication.
Important Points to Remember
Dell Networking operating software limits network access for certain users by using virtual local area
network (VLAN) assignments. 802.1X with VLAN assignment has these characteristics when configured on
the switch and the RADIUS server.
• 802.1X is supported on the S6000 platform.
• On all platforms, if the primary RADIUS server becomes unresponsive, the authenticator begins using
a secondary RADIUS server, if configured.
• If no VLAN is supplied by the RADIUS server or if you disable 802.1X authorization, the port configures
in its access VLAN after successful authentication.
• If you enable 802.1X authorization but the VLAN information from the RADIUS server is not valid, the
port returns to the Unauthorized state and remains in the configured access VLAN. This safeguard
prevents ports from appearing unexpectedly in an inappropriate VLAN due to a configuration error.
Configuration errors create an entry in Syslog.
• If you enable 802.1X authorization and all information from the RADIUS server is valid, the port is
placed in the specified VLAN after authentication.
• If you enable port security on an 802.1X port with VLAN assignment, the port is placed in the RADIUS
server assigned VLAN.
• If you disable 802.1X on the port, it returns to the configured access VLAN.
• When the port is in the Force Authorized, Force Unauthorized, or Shutdown state, it is placed in the
configured access VLAN.
• If an 802.1X port is authenticated and put in the RADIUS server assigned VLAN, any change to the port
access VLAN configuration does not take effect.
• The 802.1X with VLAN assignment feature is not supported on trunk ports, dynamic ports, or with
dynamic-access port assignment through a VLAN membership.
148
802.1X
Содержание Networking S6000 System
Страница 1: ...Dell Command Line Reference Guide for the S6000 System 9 5 0 0 ...
Страница 558: ...Version 8 3 10 0 Introduced on the S4810 558 Equal Cost Multi Path ECMP ...
Страница 579: ...Version 8 3 12 0 Introduced on the S4810 FCoE Transit 579 ...
Страница 773: ...dropped in keepalive Dell Related Commands show ip cam stack unit displays the CAM table IPv4 Routing 773 ...
Страница 1319: ...Gi1 2 2 STP PVST Dell Related Commands show running config displays the current configuration Service Provider Bridging 1319 ...
Страница 1331: ...Gi 3 40 configured rate 16384 actual rate 16384 sub sampling rate 1 Dell sFlow 1331 ...
Страница 1480: ...Version 8 3 8 0 Introduced on the S4810 1480 Virtual Link Trunking VLT ...