User’s Manual of WGSW-28040
4.9 Security
This section is to control the access of the Managed Switch, including the user access and management control.
The Security Page contains links to the following main topics:
802.1x
Radius Server
Server
AAA
Access
Management Access Method
DHCP Snooping
Dynamic ARP Inspection
IP Source Gurad
Port Security
DoS
Strom Control
4.9.1 802.1X
Overview of 802.1X (Port-based) Authentication
In the 802.1X-world, the user is called the supplicant, the switch is the authenticator, and the RADIUS server is the
authentication server. The switch acts as the man-in-the-middle, forwarding requests and responses between the supplicant
and the authentication server. Frames sent between the supplicant and the switch are special 802.1X frames, known as
EAPOL
(EAP Over LANs)
frames. EAPOL frames encapsulate
EAP PDU
s (RFC3748). Frames sent between the switch and the
RADIUS server are RADIUS packets. RADIUS packets also encapsulate EAP PDUs together with other attributes like the
switch's IP address, name, and the supplicant's port number on the switch. EAP is very flexible, in that it allows for different
authentication methods, like
MD5-Challenge
,
PEAP
, and
TLS
. The important thing is that the authenticator (the switch) doesn't
need to know which authentication method the supplicant and the authentication server are using, or how many information
exchange frames are needed for a particular method. The switch simply encapsulates the EAP part of the frame into the
relevant type (EAPOL or RADIUS) and forwards it.
When authentication is complete, the RADIUS server sends a special packet containing a success or failure indication. Besides
forwarding this decision to the supplicant, the switch uses it to open up or block traffic on the switch port connected to the
supplicant.
Overview of User Authentication
It is allowed to configure the Managed Switch to authenticate users logging into the system for management access using local
or remote authentication methods, such as telnet and Web browser. This Managed Switch provides secure network
management access using the following options:
194
Содержание wgsw-28040
Страница 1: ...User s Manual of WGSW 28040 1 ...
Страница 124: ...User s Manual of WGSW 28040 VLAN ID 3 Port 4 5 Untagged Port 6 7 Tagged Port 1 3 Excluded 124 ...
Страница 147: ...User s Manual of WGSW 28040 Figure 4 7 3 Multicast Service Figure 4 7 4 Multicast Flooding 147 ...
Страница 257: ...User s Manual of WGSW 28040 Figure 4 10 7 IP based ACE Page Screenshot 257 ...
Страница 263: ...User s Manual of WGSW 28040 Figure 4 10 11 IP based ACE Page Screenshot The page includes the following fields 263 ...