Chapter 12
| Security Measures
Network Access (MAC Address Authentication)
– 293 –
■
Intrusion
– Sets the port response to a host MAC authentication failure to
either block access to the port or to pass traffic through. (Options: Block,
Pass; Default: Block)
■
Max MAC Count
8
– Sets the maximum number of MAC addresses that can
be authenticated on a port via MAC authentication; that is, the Network
Access process described in this section. (Range: 1-1024; Default: 1024)
◆
Network Access Max MAC Count
– Sets the maximum number of MAC
addresses that can be authenticated on a port interface via all forms of
authentication (including Network Access and IEEE 802.1X). (Range: 1-2048;
Default: 1024)
◆
Guest VLAN
– Specifies the VLAN to be assigned to the port when 802.1X
Authentication or MAC authentication fails. (Range: 0-4094, where 0 means
disabled; Default: Disabled)
The VLAN must already be created and active (see
). Also, when used with 802.1X authentication, intrusion action
must be set for “Guest VLAN” (see
“Configuring Port Authenticator Settings for
).
A port can only be assigned to the guest VLAN if it failed authentication, and
switchort mode is set to Hybrid. (See
“Adding Static Members to VLANs” on
◆
Dynamic VLAN
– Enables dynamic VLAN assignment for an authenticated
port. When enabled, any VLAN identifiers returned by the RADIUS server
through the 802.1X authentication process are applied to the port, providing
the VLANs have already been created on the switch. (GVRP is not used to create
the VLANs.) (Default: Enabled)
The VLAN settings specified by the first authenticated MAC address are
implemented for a port. Other authenticated MAC addresses on the port must
have the same VLAN configuration, or they are treated as authentication
failures.
If dynamic VLAN assignment is enabled on a port and the RADIUS server
returns no VLAN configuration (to the 802.1X authentication process), the
authentication is still treated as a success, and the host is assigned to the
default untagged VLAN.
When the dynamic VLAN assignment status is changed on a port, all
authenticated addresses mapped to that port are cleared from the secure MAC
address table.
◆
Dynamic QoS
– Enables dynamic QoS assignment for an authenticated port.
(Default: Disabled)
8.
The maximum number of MAC addresses per port is 1024, and the maximum number of secure
MAC addresses supported for the switch system is 1024. When the limit is reached, all new MAC
addresses are treated as authentication failures.
Содержание GTL-2881
Страница 30: ...Figures 30 Figure 450 Showing RIP Peer Information 669 Figure 451 Resetting RIP Statistics 670 ...
Страница 34: ...Section I Getting Started 34 ...
Страница 48: ...Section II Web Configuration 48 Unicast Routing on page 651 ...
Страница 151: ...Chapter 4 Interface Configuration VLAN Trunking 151 Figure 69 Configuring VLAN Trunking ...
Страница 152: ...Chapter 4 Interface Configuration VLAN Trunking 152 ...
Страница 229: ...Chapter 8 Congestion Control Automatic Traffic Control 229 Figure 135 Configuring ATC Interface Attributes ...
Страница 230: ...Chapter 8 Congestion Control Automatic Traffic Control 230 ...
Страница 596: ...Chapter 14 Multicast Filtering Multicast VLAN Registration for IPv6 596 ...
Страница 620: ...Chapter 15 IP Configuration Setting the Switch s IP Address IP Version 6 620 ...
Страница 670: ...Chapter 18 Unicast Routing Configuring the Routing Information Protocol 670 Figure 451 Resetting RIP Statistics ...
Страница 672: ...Section III Appendices 672 ...
Страница 678: ...Appendix A Software Specifications Management Information Bases 678 ...
Страница 688: ...Appendix C License Statement GPL Code Statement Notification of Compliance 688 ...
Страница 696: ...Glossary 696 ...
Страница 706: ...GTL 2881 GTL 2882 E112016 ST R01 ...