78
Table of Contents
Linksys
•
MAC-based—Supported in all authentication modes
•
In 802 1x-based authentication, the authenticator extracts the EAP
messages from the 802 1x messages (EAPOL frames) and passes them to
the authentication server, using the RADIUS protocol
•
With MAC-based authentication, the authenticator itself executes the EAP
client part of the software
Authentication Server
An authentication server performs the actual authentication of the client The
authentication server for the device is a RADIUS authentication server with
EAP extensions
Port Administrative Authentication States
The port administrative state determines whether the client is granted access
to the network
The port administrative state can be configured in the Port Authentication page
The following values are available:
•
Force Authorized
Port authentication is disabled and the port transmits all traffic
in accordance with its static configuration without requiring any
authentication The switch sends the 802 1x EAP-packet with the EAP
success message inside when it receives the 802 1x EAPOL-start message
This is the default state
•
Force Unauthorized
Port authentication is disabled and the port transmits all traffic via
the guest VLAN For more information see Defining Host and Session
Authentication The switch sends 802 1x EAP packets with EAP failure
messages inside when it receives 802 1x EAPOL- Start messages
•
Auto
Enables 802 1 x authentications in accordance with the configured port host
mode and authentication methods configured on the port Port Host Modes
Port Host Modes
Ports can be placed in the following port host modes (configured in the Host
Authentication page):
•
Multi-Host Mode
A port is authorized if there is at least one authorized client
When a port is unauthorized and a guest VLAN is enabled, untagged
traffic is remapped to the guest VLAN Tagged traffic is dropped unless it
belongs to the guest VLAN
When a port is authorized, untagged and tagged traffic from all hosts
connected to the port is bridged, based on the static VLAN membership
port configuration
You can specify that untagged traffic from the authorized port will be
remapped to a VLAN that is assigned by a RADIUS server during the
authentication process Tagged traffic is dropped unless it belongs to the
RADIUS-assigned VLAN Radius VLAN assignment on a port is set in the
Port Authentication page
•
Multi-Sessions Mode
Unlike multi-host modes, a port in the multi-session mode does not have
an authentication status The maximum number of authorized hosts
allowed on the port is configured in the Port Authentication page
Tagged and untagged traffic from unauthorized hosts is remapped to the
guest VLAN if it is defined and enabled on the VLAN, or it is dropped if the
guest VLAN is not enabled on the port
If an authorized host is assigned a VLAN by a RADIUS server, all its tagged and
untagged traffic is bridged via the VLAN If the VLAN is not assigned, all its
traffic is bridged based on the static VLAN membership port configuration
Multiple Authentication Methods
If more than one authentication method is enabled on the switch, the
following hierarchy of authentication methods is applied:
•
802 1x Authentication: Highest
•
MAC-Based Authentication: Lowest
Multiple methods can run at the same time When one method finishes
successfully, the client becomes authorized, the methods with lower priority
are stopped and the methods with higher priority continue
When one of the authentication methods running simultaneously fails, the
other methods continue
Содержание Smart Switch LGS3XX
Страница 1: ...Smart Switch LGS3XX User Guide ...