![background image](http://html1.mh-extra.com/html/linksys/lgs308/lgs308_user-manual_1925095158.webp)
158
In this case, the switch supports EAP MD5 functionality with the username and password equal to
the client MAC address, as shown below.
Guest VLAN
The guest VLAN provide access to services that do not require the subscribing devices or ports to
be 802.1X or MAC-based authenticated and authorized. The guest VLAN is the VLAN that is
assigned to an unauthorized client. You can configure the guest VLAN and one or more VLANs to
be unauthenticated in the
Security > Network Access Control > Feature Configuration
page.
The guest VLAN, if configured, is a static VLAN with the following characteristics:
•
It must be manually defined from an existing static VLAN.
•
The guest VLAN cannot be used as the Voice VLAN.
Host Modes with Guest VLAN
The host modes work with guest VLAN in Single-Host and Multi-Host Mode.
Untagged traffic and tagged traffic belonging to the guest VLAN arriving on an unauthorized port
are bridged via the guest VLAN. All other traffic is discarded.
Dynamic VLAN Assignment
An authorized client can be assigned a VLAN by the RADIUS server, if this option is enabled in the
Port Authentication page. This is called either Dynamic VLAN Assignment (DVA) or RADIUS-
Assigned VLAN. In this guide, RADIUS-Assigned VLAN is used.
When a port is in multi-session mode and RADIUS-Assigned VLAN is enabled, the device
automatically adds the port as an untagged member of the VLAN that is assigned by the RADIUS
server during the authentication process. The device classifies untagged packets to the assigned
VLAN if the packets originated from the devices or ports that are authenticated and authorized.
Note
—In multi-session mode, RADIUS VLAN assignment is only supported when the device is in
Layer 2 system mode.
Содержание LGS308
Страница 1: ...1 User Guide SMART SWITCH LGS3XX...