Network Administration: Security
249
FILE LOCATION: C:\Users\gina\Desktop\Checkout_new\Dell Astute\User
Guide\Dell_Astute_Network_Admin_Security.fm
D E L L CO N F I D E N T I A L – P R E L I M I N A RY 8 / 9 / 16 - F O R P RO O F O N L Y
• The member ports must be trunk and/or general ports. An access port
cannot be member of an unauthenticated VLAN.
The Guest VLAN, if configured, is a static VLAN with the following
characteristics.
• It must be manually defined from an existing, static VLAN.
• It is automatically available only to unauthorized devices, or to ports of
devices that are connected and Guest VLAN enabled.
• If a port is Guest-VLAN-enabled, the switch automatically adds the port as
an untagged member of the Guest VLAN when the port is not authorized,
and removes the port from the Guest VLAN when the first supplicant of
the port is authorized.
• The Guest VLAN cannot be used as both the Voice VLAN and an
unauthenticated VLAN.
The switch also uses the Guest VLAN for authentication at ports configured
with Multiple Session mode and MAC-based authentication. Therefore, you
must configure a Guest VLAN before you can use the MAC-based
authentication mode.
For authentication to function, it must be activated both globally, in the
page and individually on each port, in the
Based Authentication Interface Settings
pages.
Port-Based Authentication Global
To globally configure authentication:
1
Click
Network Administration
>
Security
>
Dot1 Authentications
>
Port Based Authentication - Global
.
2
Enter the following fields:
–
Port Based Authentication State
— Enable/disable port-based
authentication.
–
Authentication Method
— Select an authentication method. The
possible options are:
•
RADIUS, None
— Perform port authentication first by using the
RADIUS server. If no response is received from RADIUS (for
example, if the server is down), then no authentication is
performed, and the session is permitted.