224
SIGNAMAX LLC • www.signamax.eu
the device encapsulates the EAP data sent from the authentication server into the
EAPOL packets and transmits to client.
We call this kind of interactive mode as the EAP relay. The EAP relay requests that the
authentication server supports the EAP protocol; otherwise the authentication server
cannot interact with the client by using EAP. Consider about the practical application
environment, the authentication server that was deployed earlier may not support the
EAP protocol.
Signamax series switches expand this and support the EAP termination mode. The EAP
data from the client is not transmitted directly to the authentication server, but the
device completes the EAP interaction with the client and picks up the authentication
information of the user and then transmits it to the authentication server to
authenticate.
Auto Vlan
After an 802.1X user passed authentication on the server, the server transmits the
authorization information to the device. If the server is enabled with the VLAN assigning
function, the assigned VLAN information is included in the authorization information. The
device adds the port to the assigned VLAN. We call the assigned VLAN as the Auto VLAN.
•
If the RADIUS server authentication information doesn’t have the assigned VLAN
information, the attributes of the port VLAN are not changed after the authentication is
passed.
•
If RADIUS server authentication information has the assigned VLAN information, judge
if the assigned auto VLAN exists after the authentication is passed. If it exists, add the
port into the Auto VLAN with untag mode, and the default VID of the port is the VID of
the Auto VLAN; if the Auto VLAN doesn’t exist, the attributes of the port VLAN are not
changed, and the authentication is failed.
•
After the user goes offline, the port is returned to the “not authenticated” status and is
deleted from the Auto VLAN. The default VID of the port is also returned to the original
VID.
The assigned Auto VLAN neither changes nor affects the configuration of a port.
However,
as the assigned VLAN has higher priority than the user-configured VLAN (that is Config
VLAN), it is the Auto VLAN that takes effect after a user passed authentication. The user
configured VLAN takes effect after the user goes offline.
Содержание 065-7434
Страница 1: ...24 Port 10 100 L3 Switch Model 065 7434 Configuration Guide Revision A1 ...
Страница 245: ...245 SIGNAMAX LLC www signamax eu Application Example Example of configuring DHCP Snooping ...
Страница 302: ...302 SIGNAMAX LLC www signamax eu Default status no switching interface ...
Страница 368: ......
Страница 655: ...287 SIGNAMAX LLC www signamax eu Sub VLAN members in the system ...