![Dell PowerConnect M6220 Скачать руководство пользователя страница 487](http://html.mh-extra.com/html/dell/powerconnect-m6220/powerconnect-m6220_user-configuration-manual_84547487.webp)
Configuring Port and System Security
487
Client devices that are 802.1X-supplicant-enabled authenticate with the
switch when they are plugged into the 802.1X-enabled switch port. The
switch verifies the credentials of the client by communicating with an
authentication server. If the credentials are verified, the authentication server
informs the switch to
unblock
the switch port and allows the client
unrestricted access to the network; i.e., the client is a member of an internal
VLAN.
Guest VLAN mode can be configured on a per-port basis. If a client does not
attempt authentication on a port, and the port is configured for the guest
VLAN, the client is assigned to the guest VLAN configured on that port. The
port is assigned a guest VLAN ID and is moved to the authorized status.
When the guest VLAN is disabled, users authorized by the guest VLAN are
removed.
What is Monitor Mode?
The monitor mode is a special mode that can be enabled in conjunction with
802.1X authentication. Monitor mode provides a way for network
administrators to identify possible issues with the 802.1X configuration on
the switch without affecting the network access to the users of the switch. It
allows network access even in case where there is a failure to authenticate but
logs the results of the authentication process for diagnostic purposes.
The monitor mode can be configured globally on a switch. If the switch fails
to authenticate a user for any reason (for example, RADIUS access reject
from RADIUS server, RADIUS timeout, or the client itself is Dot1x unaware),
the client is authenticated and is undisturbed by the failure condition(s). The
reasons for failure are logged for tracking purposes.
Table 19-1 provides a summary of the 802.1X Monitor Mode behavior.
Table 19-1. IEEE 802.1X Monitor Mode Behavior
Case
Sub-case
Regular Dot1x
Dot1x Monitor Mode
RADIUS/IAS
Success
Success
Port State: Permit
VLAN: Assigned
Filter: Assigned
Port State: Permit
VLAN: Assigned
Filter: Assigned
Incorrect NAS Port Port State: Deny
Port State: Permit
VLAN: Default PVID
of the port
Содержание PowerConnect M6220
Страница 52: ...52 Introduction ...
Страница 86: ...86 Switch Features ...
Страница 100: ...100 Hardware Overview ...
Страница 116: ...116 Using the Command Line Interface ...
Страница 121: ...Default Settings 121 ...
Страница 122: ...122 Default Settings ...
Страница 142: ...142 Setting Basic Network Information ...
Страница 206: ...206 Configuring Authentication Authorization and Accounting ...
Страница 292: ...292 Managing General System Settings Figure 11 31 Verify MOTD ...
Страница 296: ...296 Managing General System Settings ...
Страница 332: ...332 Configuring SNMP ...
Страница 408: ...408 Monitoring Switch Traffic ...
Страница 560: ...560 Configuring Access Control Lists ...
Страница 582: ...582 Configuring VLANs Figure 21 6 Add Ports to VLAN 4 Click Apply 5 Verify that the ports have been added to the VLAN ...
Страница 591: ...Configuring VLANs 591 Figure 21 17 GVRP Port Parameters Table ...
Страница 597: ...Configuring VLANs 597 Figure 21 24 Double VLAN Port Parameter Table ...
Страница 693: ...Configuring Port Based Traffic Control 693 Figure 24 3 Storm Control 5 Click Apply ...
Страница 780: ...780 Configuring Connectivity Fault Management ...
Страница 804: ...804 Snooping and Inspecting Traffic Figure 27 17 DAI Interface Configuration Summary ...
Страница 818: ...818 Snooping and Inspecting Traffic ...
Страница 836: ...836 Configuring Link Aggregation ...
Страница 860: ...860 Configuring Data Center Bridging Features ...
Страница 906: ...906 Configuring DHCP Server Settings ...
Страница 940: ...940 Configuring L2 and L3 Relay Features Figure 34 3 DHCP Relay Interface Summary ...
Страница 1080: ...1080 Configuring VRRP ...
Страница 1104: ...1104 Configuring IPv6 Routing ...
Страница 1124: ...1124 Configuring DHCPv6 Server and Relay Settings Relay Interface Number Vl100 Relay Remote ID Option Flags ...
Страница 1131: ...Configuring Differentiated Services 1131 Figure 40 5 DiffServ Class Criteria ...
Страница 1158: ...1158 Configuring Class of Service Figure 41 1 Mapping Table Configuration CoS 802 1P ...
Страница 1174: ...1174 Configuring Auto VoIP Figure 42 2 Auto VoIP Interface Configuration ...
Страница 1240: ...1240 Managing IPv4 and IPv6 Multicast Figure 43 51 DVMRP Next Hop Summary ...
Страница 1266: ...1266 Managing IPv4 and IPv6 Multicast ...
Страница 1274: ...1274 System Process Definitions ...
Страница 1294: ...1294 Index ...