C
HAPTER
14
| Security Measures
Configuring 802.1X Port Authentication
– 350 –
In this mode, only one host connected to a port needs to pass
authentication for all other hosts to be granted network access.
Similarly, a port can become unauthorized for all hosts if one
attached host fails re-authentication or sends an EAPOL logoff
message.
n
MAC-Based
– Allows multiple hosts to connect to this port, with
each host needing to be authenticated.
In this mode, each host connected to a port needs to pass
authentication. The number of hosts allowed access to a port
operating in this mode is limited only by the available space in the
secure address table (i.e., up to 1024 addresses).
u
Max MAC Count
– The maximum number of hosts that can connect to
a port when the Multi-Host operation mode is selected.
(Range: 1-1024; Default: 5)
u
Max Request
– Sets the maximum number of times the switch port
will retransmit an EAP request packet to the client before it times out
the authentication session. (Range: 1-10; Default 2)
u
Quiet Period
– Sets the time that a switch port waits after the Max
Request Count has been exceeded before attempting to acquire a new
client. (Range: 1-65535 seconds; Default: 60 seconds)
u
Tx Period
– Sets the time period during an authentication session that
the switch waits before re-transmitting an EAP packet.
(Range: 1-65535; Default: 30 seconds)
u
Supplicant Timeout
– Sets the time that a switch port waits for a
response to an EAP request from a client before re-transmitting an EAP
packet. (Range: 1-65535; Default: 30 seconds)
This command attribute sets the timeout for EAP-request frames other
than EAP-request/identity frames. If dot1x authentication is enabled on
a port, the switch will initiate authentication when the port link state
comes up. It will send an EAP-request/identity frame to the client to
request its identity, followed by one or more requests for authentication
information. It may also send other EAP-request frames to the client
during an active connection as required for reauthentication.
u
Server Timeout
– Sets the time that a switch port waits for a response
to an EAP request from an authentication server before re-transmitting
an EAP packet. (Fixed Setting: 10 seconds)
u
Re-authentication Status
– Sets the client to be re-authenticated
after the interval specified by the Re-authentication Period. Re-
authentication can be used to detect if a new device is plugged into a
switch port. (Default: Disabled)
u
Re-authentication Period
– Sets the time period after which a
connected client must be re-authenticated. (Range: 1-65535 seconds;
Default: 3600 seconds)
Содержание DG-GS4826S
Страница 2: ...DG GS4826S DG GS4850S E012011 R01 F1 2 2 0 ...
Страница 4: ......
Страница 6: ...ABOUT THIS GUIDE 6 ...
Страница 60: ...SECTION I Getting Started 60 ...
Страница 72: ...CHAPTER 1 Introduction System Defaults 72 ...
Страница 90: ...CHAPTER 2 Initial Switch Configuration Managing System Files 90 ...
Страница 92: ...SECTION II Web Configuration 92 u Unicast Routing on page 539 u Multicast Routing on page 595 ...
Страница 137: ...CHAPTER 4 Basic Management Tasks Resetting the System 137 Figure 23 Restarting the Switch Regularly ...
Страница 138: ...CHAPTER 4 Basic Management Tasks Resetting the System 138 ...
Страница 204: ...CHAPTER 6 VLAN Configuration Configuring MAC based VLANs 204 ...
Страница 212: ...CHAPTER 7 Address Table Settings Clearing the Dynamic Address Table 212 ...
Страница 238: ...CHAPTER 9 Rate Limit Configuration 238 Figure 106 Configuring Rate Limits ...
Страница 268: ...CHAPTER 12 Quality of Service Attaching a Policy Map to a Port 268 ...
Страница 368: ...CHAPTER 14 Security Measures DHCP Snooping 368 ...
Страница 422: ...CHAPTER 15 Basic Administration Protocols Remote Monitoring 422 ...
Страница 466: ...CHAPTER 16 Multicast Filtering Multicast VLAN Registration 466 Figure 273 Showing All MVR Groups Assigned to a Port ...
Страница 487: ...CHAPTER 17 IP Configuration Setting the Switch s IP Address IP Version 6 487 Figure 285 Showing Reported MTU Values ...
Страница 488: ...CHAPTER 17 IP Configuration Setting the Switch s IP Address IP Version 6 488 ...
Страница 538: ...CHAPTER 20 IP Services Forwarding UDP Service Requests 538 ...
Страница 594: ...CHAPTER 21 Unicast Routing Configuring the Open Shortest Path First Protocol Version 2 594 ...
Страница 624: ...CHAPTER 22 Multicast Routing Configuring PIMv6 for IPv6 624 ...
Страница 638: ...CHAPTER 23 Using the Command Line Interface CLI Command Groups 638 ...
Страница 712: ...CHAPTER 26 SNMP Commands 712 ...
Страница 720: ...CHAPTER 27 Remote Monitoring Commands 720 ...
Страница 776: ...CHAPTER 29 Authentication Commands Management IP Filter 776 ...
Страница 876: ...CHAPTER 34 Port Mirroring Commands Local Port Mirroring Commands 876 ...
Страница 898: ...CHAPTER 37 Address Table Commands 898 ...
Страница 998: ...CHAPTER 41 Quality of Service Commands 998 ...
Страница 1060: ...CHAPTER 42 Multicast Filtering Commands MLD Proxy Routing 1060 ...
Страница 1078: ...CHAPTER 43 LLDP Commands 1078 ...
Страница 1088: ...CHAPTER 44 Domain Name Service Commands 1088 ...
Страница 1164: ...CHAPTER 47 IP Interface Commands IPv6 to IPv4 Tunnels 1164 ...
Страница 1260: ...CHAPTER 48 IP Routing Commands Open Shortest Path First OSPFv3 1260 ...
Страница 1304: ...SECTION IV Appendices 1304 ...
Страница 1310: ...APPENDIX A Software Specifications Management Information Bases 1310 ...
Страница 1343: ...DG GS4826S DG GS4850S E012011 R02 F1 2 2 0 ...
Страница 1344: ......