![SNR S2940-8G-v2 Скачать руководство пользователя страница 314](http://html1.mh-extra.com/html/snr/s2940-8g-v2/s2940-8g-v2_configuration-manual_1310630314.webp)
SNR S2940-8G-v2 Switch Configuration Guide
802.1x Configuration
Supplicant
PAE
Authenticator
System PAE
RADIUS
server
EAPOL-Start
EAP-Request/Identity
EAP-Response/Identity
RADIUS Access-Request
(EAP-Response/Identity)
EAP-Request/PEAP Start
RADIUS Access-Challenge
(EAP-Request/PEAP Start)
EAP-Response(Empty)
RADIUS Access-Request
EAP-Response(Empty)
EAP-Request/MD5 Challenge
RADIUS Access-Challenge
(EAP-Request/MD5 Challenge)
EAPOL
EAPOR
TLS Channel Established
...
...
EAP-Response/MD5 Password
RADIUS Access-Request
(EAP-Response/MD5 Password)
EAP-Success
RADIUS Access-Accept
(EAP-Success)
Figure 45.11: the Authentication Flow of 802.1x PEAP
this method: standard control and advanced control. The user-based standard control
will not restrict the access to limited resources, which means all users of this port can
access limited resources before being authenticated. The user-based advanced con-
trol will restrict the access to limited resources, only some particular users of the port
can access limited resources before being authenticated. Once those users pass the
authentication, they can access all resources.
Attention:
when using private supplicant systems, user-based advanced control is recom-
mended to effectively prevent ARP cheat.
For the maximum number of the authenticated users, the maximum number of IPv4 users
supported by user-based is 400, the maximum number of IPv6 users supported by user-based is
800. mac-based relates to ratelimit value of switch, it can supports 4000 authenticated users, but
it is recommended that the number of the authenticated users should not exceed 2000.
45.1.7
The Features of VLAN Allocation
1. Auto VLAN
Auto VLAN feature enables RADIUS server to change the VLAN to which the access port be-
longs, based on the user information and the user access device information. When an 802.1x
user passes authentication on the server, the RADIUS server will send the authorization infor-
mation to the device, if the RADIUS server has enabled the VLAN-assigning function, then the
following attributes should be included in the Access-Accept messages:
• Tunnel-Type = VLAN (13)
314
Содержание S2940-8G-v2
Страница 11: ...SNR S2940 8G v2 Switch Configuration Guide Part I Basic Management Configuration 11...
Страница 46: ...SNR S2940 8G v2 Switch Configuration Guide Part II Port Configuration 46...
Страница 123: ...SNR S2940 8G v2 Switch Configuration Guide Part III VLAN and MAC Table Configuration 123...
Страница 164: ...SNR S2940 8G v2 Switch Configuration Guide Part IV MSTP Configuration 164...
Страница 176: ...SNR S2940 8G v2 Switch Configuration Guide Part V QoS and Flow based Redirection Configuration 176...
Страница 198: ...SNR S2940 8G v2 Switch Configuration Guide Part VI L3 Forward and ARP Configuration 198...
Страница 218: ...SNR S2940 8G v2 Switch Configuration Guide Part VII DHCP Configuration 218...
Страница 257: ...SNR S2940 8G v2 Switch Configuration Guide Part VIII Multicast Protocol 257...
Страница 278: ...SNR S2940 8G v2 Switch Configuration Guide Part IX Security Function Configuration 278...
Страница 376: ...SNR S2940 8G v2 Switch Configuration Guide Part X Reliability Configuration 376...
Страница 395: ...SNR S2940 8G v2 Switch Configuration Guide Part XI Flow Monitor Configuration 395...
Страница 403: ...SNR S2940 8G v2 Switch Configuration Guide Part XII Network Time Management Configuration 403...
Страница 411: ...SNR S2940 8G v2 Switch Configuration Guide Part XIII Debugging and Diagnosis 411...