
C
HAPTER
13
| Security Measures
Configuring 802.1X Port Authentication
– 314 –
hosts if one attached host fails re-authentication or sends an EAPOL logoff
message.
Figure 171: Configuring Port Security
The operation of 802.1X on the switch requires the following:
◆
The switch must have an IP address assigned.
◆
RADIUS authentication must be enabled on the switch and the IP
address of the RADIUS server specified.
◆
802.1X must be enabled globally for the switch.
◆
Each switch port that will be used must be set to dot1X “Auto” mode.
◆
Each client that needs to be authenticated must have dot1X client
software installed and properly configured.
◆
The RADIUS server and 802.1X client support EAP. (The switch only
supports EAPOL in order to pass the EAP packets from the server to the
client.)
◆
The RADIUS server and client also have to support the same EAP
authentication type – MD5, PEAP, TLS, or TTLS. (Native support for
these encryption methods is provided in Windows XP, and in Windows
2000 with Service Pack 4. To support these encryption methods in
Windows 95 and 98, you can use the AEGIS dot1x client or other
comparable client software)
C
ONFIGURING
802.1X
G
LOBAL
S
ETTINGS
Use the Security > Port Authentication (Configure Global) page to
configure IEEE 802.1X port authentication. The 802.1X protocol must be
enabled globally for the switch system before port settings are active.
CLI R
EFERENCES
◆
"802.1X Port Authentication" on page 693
802.1x
client
RADIUS
server
1. Client attempts to access a switch port.
2. Switch sends client an identity request.
3. Client sends back identity information.
4. Switch forwards this to authentication server.
5. Authentication server challenges client.
6. Client responds with proper credentials.
7. Authentication server approves access.
8. Switch grants client access to this port.
Содержание ECS4610-24F
Страница 1: ...Management Guide www edge core com ECS4610 24F 24 Port Layer 3 Gigabit Ethernet Switch...
Страница 2: ......
Страница 4: ......
Страница 6: ...ABOUT THIS GUIDE 6...
Страница 36: ...CONTENTS 36...
Страница 48: ...FIGURES 48...
Страница 54: ...TABLES 54...
Страница 56: ...SECTION I Getting Started 56...
Страница 78: ...CHAPTER 2 Initial Switch Configuration Managing System Files 78...
Страница 80: ...SECTION II Web Configuration 80 Unicast Routing on page 483 Multicast Routing on page 541...
Страница 100: ...CHAPTER 3 Using the Web Interface Navigating the Web Browser Interface 100...
Страница 123: ...CHAPTER 4 Basic Management Tasks Resetting the System 123 Figure 22 Restarting the Switch Regularly...
Страница 124: ...CHAPTER 4 Basic Management Tasks Resetting the System 124...
Страница 186: ...CHAPTER 6 VLAN Configuration Configuring MAC based VLANs 186...
Страница 194: ...CHAPTER 7 Address Table Settings Clearing the Dynamic Address Table 194...
Страница 218: ...CHAPTER 8 Spanning Tree Algorithm Configuring Interface Settings for MSTP 218...
Страница 220: ...CHAPTER 9 Rate Limit Configuration 220 Figure 103 Configuring Rate Limits...
Страница 222: ...CHAPTER 10 Storm Control Configuration 222 Figure 104 Configuring Broadcast Storm Control...
Страница 238: ...CHAPTER 11 Quality of Service Attaching a Policy Map to a Port 238...
Страница 334: ...CHAPTER 13 Security Measures DHCP Snooping 334...
Страница 429: ...CHAPTER 15 Multicast Filtering Multicast VLAN Registration 429 Figure 257 Showing All MVR Groups Assigned to a Port...
Страница 430: ...CHAPTER 15 Multicast Filtering Multicast VLAN Registration 430...
Страница 540: ...CHAPTER 20 Unicast Routing Configuring the Open Shortest Path First Protocol Version 2 540...
Страница 564: ...CHAPTER 21 Multicast Routing Configuring PIM for IPv4 564 Figure 375 Showing RP Mapping...
Страница 578: ...CHAPTER 22 Using the Command Line Interface CLI Command Groups 578...
Страница 628: ...CHAPTER 24 System Management Commands Time Range 628...
Страница 648: ...CHAPTER 25 SNMP Commands 648...
Страница 656: ...CHAPTER 26 Remote Monitoring Commands 656...
Страница 786: ...CHAPTER 30 Interface Commands 786...
Страница 800: ...CHAPTER 32 Port Mirroring Commands Local Port Mirroring Commands 800...
Страница 902: ...CHAPTER 38 Quality of Service Commands 902...
Страница 950: ...CHAPTER 39 Multicast Filtering Commands IGMP Proxy Routing 950...
Страница 968: ...CHAPTER 40 LLDP Commands 968...
Страница 978: ...CHAPTER 41 Domain Name Service Commands 978...
Страница 1084: ...CHAPTER 45 IP Routing Commands Open Shortest Path First OSPFv2 1084...
Страница 1114: ...SECTION IV Appendices 1114...
Страница 1120: ...APPENDIX A Software Specifications Management Information Bases 1120...
Страница 1142: ...COMMAND LIST 1142...
Страница 1152: ...INDEX 1152...
Страница 1153: ......
Страница 1154: ...ECS4610 24F E052010 ST R01 149100000092A...