81
Table of Contents
Linksys
•
Guest VLAN—Enable the use of a guest VLAN for unauthorized ports If
a guest VLAN is enabled, all unauthorized ports automatically join the
VLAN selected in the Guest VLAN ID field If a port is later authorized, it is
removed from the guest VLAN
•
Guest VLAN ID—Select the guest VLAN from the list of VLANs
STEP 3
Click Apply The settings are written to the Running Configuration file
Port Authentication
The Port Authentication page enables configuration of 802 1X parameters
for a port Since some of the configuration changes are only possible while
the port is in Force Authorized state, such as host authentication, it is
recommended that you change the port control to Force Authorized before
making changes When the configuration is complete return the port control
to its previous state
NOTE:
A port with 802 1x defined on it cannot become a member of a LAG
To configure 802 1X authentication:
STEP 1 Click Configuration > Security > Network Access Control >
Port Authentication
This page displays the authentication settings for all ports
STEP 2
Select a port, and click Edit
STEP 3
Enter the parameters
•
Interface—Select a port
•
Port Control—Select the Administrative Port Authorization state The
options are:
•
Force Unauthorized—Denies the interface access by moving the
interface into the unauthorized state The device does not provide
authentication services to the client through the interface
•
Auto—Enables port-based authentication and authorization on the
device The interface moves between an authorized or unauthorized
state based on the authentication exchange between the device and
the client
•
Force Authorized—Authorizes the interface without authentication
•
Host Authentication Mode—Select one of the following options:
•
Multiple Host (802 1x)—Supports port-based authentication with
multiple clients per port
•
Multiple Sessions—Supports client-based authentication with
multiple clients per port
•
RADIUS VLAN Assignment—Select to enable Dynamic VLAN assignment
on the selected port
•
Guest VLAN— Select to enable Guest VLAN
After an authentication failure, and if guest VLAN is activated globally on a
given port, the guest VLAN is automatically assigned
•
802 1X Based Authentication—Select to enable 802 1X authentication on
the port
•
MAC Based Authentication—Select to enabled MAC-based
authentication on the port The port is authenticated based on the
supplicant MAC address Only 8 MAC-based authentications can be used
on the port
NOTE:
For MAC authentication to succeed, the RADIUS server supplicant username
and password must be the supplicant MAC address The MAC address
must be in lower case letters and entered without the or - separators; for
example: 0020aa00bbcc
•
Periodic Reauthentication—Select to enable port re-authentication
attempts after the specified Reauthentication Period
•
Reauthentication Period—Enter the number of seconds after which the
selected port is reauthenticated
STEP 4
Click Apply The port settings are written to the Running
Configuration file
Authenticated Hosts
To display details about authenticated users, do the following:
STEP 1
Click Configuration > Security > Network Access Control >
Authenticated Hosts
This page displays the following fields:
•
User Name—Supplicant names that were authenticated on each port
•
MAC Address—Displays the supplicant MAC address
Содержание Smart Switch LGS3XX
Страница 1: ...Smart Switch LGS3XX User Guide ...