Chapter 4: Web management
194
NS3550-8T-2S Industrial Managed Switch User Manual
servers, or the back end servers, determine if the user is allowed access to the
network. These back end (RADIUS) servers are configured on the "Configuration >
Security > AAA" page. The IEEE802.1X standard defines port-based operation, but
non-standard variants overcome security limitations.
MAC-based authentication permits authentication of more than one user on the same
port, and doesn't require the user to have special 802.1X supplicant software installed
on the system. The switch uses the MAC address to authenticate against the back end
server. Intruders can create counterfeit MAC addresses, which makes MAC-based
authentication less secure than 802.1X authentication. The NAS configuration consists
of two sections, a system- and a port-wide.