Chapter 12
| Security Measures
Network Access (MAC Address Authentication)
– 246 –
The maximum number of secure MAC addresses supported for the switch
system is 1024.
Web Interface
To configure aging status and reauthentication time for MAC address
authentication:
1.
Click Security, Network Access.
2.
Select Configure Global from the Step list.
3.
Enable or disable aging for secure addresses, and modify the reauthentication
time as required.
4.
Click Apply.
Figure 156: Configuring Global Settings for Network Access
Configuring
Network Access
for Ports
Use the Security > Network Access (Configure Interface - General) page to
configure MAC authentication on switch ports, including enabling address
authentication, setting the maximum MAC count, and enabling dynamic VLAN or
dynamic QoS assignments.
Parameters
These parameters are displayed:
◆
Guest VLAN
– Specifies the VLAN to be assigned to the port when 802.1X
Authentication or MAC authentication fails. (Range: 0-4094, where 0 means
disabled; Default: Disabled)
The VLAN must already be created and active (see
). Also, when used with 802.1X authentication, intrusion action
must be set for “Guest VLAN” (see
“Configuring Port Authenticator Settings for
).
A port can only be assigned to the guest VLAN in case of failed authentication,
and switchport mode is set to Hybrid. (See
“Adding Static Members to VLANs”
.)
◆
Dynamic VLAN
– Enables dynamic VLAN assignment for an authenticated
port. When enabled, any VLAN identifiers returned by the RADIUS server
through the 802.1X authentication process are applied to the port, providing
Содержание GEL-1061
Страница 14: ...Contents 14...
Страница 28: ...Section I Getting Started 28...
Страница 38: ...Chapter 1 Introduction System Defaults 38...
Страница 40: ...Section II Web Configuration 40...
Страница 60: ...Chapter 2 Using the Web Interface Navigating the Web Browser Interface 60...
Страница 164: ...Chapter 6 Address Table Settings Issuing MAC Address Traps 164...
Страница 192: ...Chapter 8 Congestion Control Storm Control 192...
Страница 204: ...Chapter 9 Class of Service Layer 3 4 Priority Settings 204...
Страница 216: ...Chapter 10 Quality of Service Attaching a Policy Map to a Port 216...
Страница 430: ...Chapter 14 Multicast Filtering MLD Snooping Snooping and Query for IPv4 430...
Страница 436: ...Chapter 15 IP Tools Address Resolution Protocol 436...
Страница 450: ...Chapter 16 IP Services Dynamic Host Configuration Protocol 450 Figure 301 Enabling Dynamic Provisioning via DHCP...
Страница 474: ...Section III Appendices 474...
Страница 492: ...Glossary 492...
Страница 500: ...E052016 ST R02 150200001416A...