Chapter 12
| Security Measures
Configuring 802.1X Port Authentication
– 294 –
Configuring
Port Authenticator
Settings for 802.1X
Use the Security > Port Authentication (Configure Interface – Authenticator) page
to configure 802.1X port settings for the switch as the local authenticator. When
802.1X is enabled, you need to configure the parameters for the authentication
process that runs between the client and the switch (i.e., authenticator), as well as
the client identity lookup process that runs between the switch and authentication
server.
Command Usage
◆
When the switch functions as a local authenticator between supplicant devices
attached to the switch and the authentication server, configure the parameters
for the exchange of EAP messages between the authenticator and clients on
the Authenticator configuration page.
◆
This switch can be configured to serve as the authenticator on selected ports
by setting the Control Mode to Auto on this configuration page, and as a
supplicant on other ports by the setting the control mode to Force-Authorized
on this page and enabling the PAE supplicant on the Supplicant configuration
page.
Parameters
These parameters are displayed:
◆
Port
– Port number.
◆
Status
– Indicates if authentication is enabled or disabled on the port. The
status is disabled if the control mode is set to Force-Authorized.
◆
Authorized
– Displays the 802.1X authorization status of connected clients.
■
Yes
– Connected client is authorized.
■
N/A
– Connected client is not authorized, or port is not connected.
◆
Control Mode
– Sets the authentication mode to one of the following options:
■
Auto
– Requires a dot1x-aware client to be authorized by the
authentication server. Clients that are not dot1x-aware will be denied
access.
■
Force-Authorized
– Forces the port to grant access to all clients, either
dot1x-aware or otherwise. (This is the default setting.)
■
Force-Unauthorized
– Forces the port to deny access to all clients, either
dot1x-aware or otherwise.
◆
Operation Mode
– Allows single or multiple hosts (clients) to connect to an
802.1X-authorized port. (Default: Single-Host)
■
Single-Host
– Allows only a single host to connect to this port.
Содержание GEL-1061
Страница 14: ...Contents 14...
Страница 28: ...Section I Getting Started 28...
Страница 38: ...Chapter 1 Introduction System Defaults 38...
Страница 40: ...Section II Web Configuration 40...
Страница 60: ...Chapter 2 Using the Web Interface Navigating the Web Browser Interface 60...
Страница 164: ...Chapter 6 Address Table Settings Issuing MAC Address Traps 164...
Страница 192: ...Chapter 8 Congestion Control Storm Control 192...
Страница 204: ...Chapter 9 Class of Service Layer 3 4 Priority Settings 204...
Страница 216: ...Chapter 10 Quality of Service Attaching a Policy Map to a Port 216...
Страница 430: ...Chapter 14 Multicast Filtering MLD Snooping Snooping and Query for IPv4 430...
Страница 436: ...Chapter 15 IP Tools Address Resolution Protocol 436...
Страница 450: ...Chapter 16 IP Services Dynamic Host Configuration Protocol 450 Figure 301 Enabling Dynamic Provisioning via DHCP...
Страница 474: ...Section III Appendices 474...
Страница 492: ...Glossary 492...
Страница 500: ...E052016 ST R02 150200001416A...