C
HAPTER
4
| Configuring the Switch
Configuring 802.1X Port Authentication
– 83 –
U
SAGE
G
UIDELINES
When 802.1X is enabled, you need to configure the parameters for the
authentication process that runs between the client and the switch (i.e.,
authenticator), as well as the client identity lookup process that runs
between the switch and authentication server. These parameters are
described in this section.
P
ARAMETERS
The following parameters are displayed on the Port Security Configuration
page:
System Configuration
◆
Mode
- Indicates if 802.1X and MAC-based authentication are globally
enabled or disabled on the switch. If globally disabled, all ports are
allowed to forward frames.
◆
Reauthentication Enabled
- Sets the client to be re-authenticated
after the interval specified by the Re-authentication Period. Re-
authentication can be used to detect if a new device is plugged into a
switch port. (Default: Disabled)
For MAC-based ports, reauthentication is only useful if the RADIUS
server configuration has changed. It does not involve communication
between the switch and the client, and therefore does not imply that a
client is still present on a port (see Age Period below).
◆
Reauthentication Period
- Sets the time period after which a
connected client must be re-authenticated. (Range: 1-3600 seconds;
Default: 3600 seconds)
◆
EAP Timeout
- Sets the time the switch waits for a supplicant
response during an authentication session before retransmitting an EAP
packet. (Range: 1-255; Default: 30 seconds)
◆
Age Period
- The period used to calculate when to age out a client
allowed access to the switch through MAC-based authentication as
described below. (Range: 10-1000000 seconds; Default: 300 seconds)
Suppose a client is connected to a 3rd party switch or hub, which in
turn is connected to a port on this switch that is running MAC-based
authentication, and suppose the client gets successfully authenticated.
Now assume that the client powers down his PC. What should make the
switch forget about the authenticated client? Reauthentication will not
solve this problem, since this doesn't require the client to be present,
as discussed under Reauthentication Enabled above. The solution is
aging out authenticated clients.
A timer is started when the client gets authenticated. After half the age
period, the switch starts looking for frames sent by the client. If
another half age period elapses and no frames are seen, the client is
considered removed from the system, and it will have to authenticate
again the next time a frame is seen from it. If, on the other hand, the
client transmits a frame before the second half of the age period
Содержание 8028L2
Страница 1: ...MANAGEMENT GUIDE TigerSwitchTM 10 100 1000 28 Port Gigabit Ethernet Switch SMC8028L2 ...
Страница 6: ...ABOUT THIS GUIDE 6 ...
Страница 22: ...FIGURES 22 ...
Страница 26: ...SECTION Getting Started 26 ...
Страница 46: ...CHAPTER 2 Initial Switch Configuration Managing System Files 46 ...
Страница 48: ...SECTION Web Configuration 48 ...
Страница 133: ...CHAPTER 4 Configuring the Switch Simple Network Management Protocol 133 Figure 34 SNMP System Configuration ...
Страница 144: ...CHAPTER 4 Configuring the Switch Configuring DHCP Relay and Option 82 Information 144 ...
Страница 184: ...CHAPTER 6 Performing Basic Diagnostics Running Cable Diagnostics 184 ...
Страница 238: ...CHAPTER 12 Port Commands 238 ...
Страница 244: ...CHAPTER 13 Link Aggregation Commands 244 ...
Страница 262: ...CHAPTER 15 RSTP Commands 262 ...
Страница 272: ...CHAPTER 16 IEEE 802 1X Commands 272 ...
Страница 282: ...CHAPTER 17 IGMP Commands 282 ...
Страница 290: ...CHAPTER 18 LLDP Commands 290 ...
Страница 296: ...CHAPTER 19 MAC Commands 296 ...
Страница 306: ...CHAPTER 21 PVLAN Commands 306 ...
Страница 318: ...CHAPTER 22 QoS Commands 318 ...
Страница 352: ...CHAPTER 26 SNMP Commands 352 ...
Страница 355: ...CHAPTER 27 HTTPS Commands 355 EXAMPLE HTTPS redirect enable HTTPS ...
Страница 356: ...CHAPTER 27 HTTPS Commands 356 ...
Страница 362: ...CHAPTER 29 UPnP Commands 362 ...
Страница 370: ...CHAPTER 31 Firmware Commands 370 ...
Страница 372: ...SECTION Appendices 372 ...
Страница 386: ...GLOSSARY 386 ...
Страница 390: ...INDEX 390 W web interface access requirements 49 configuration buttons 50 home page 50 menu list 51 panel display 51 ...
Страница 391: ...INDEX 391 ...
Страница 392: ...149100000079A R01 SMC8028L2 ...