
SW3
GIGABIT/FAST ETHERNET SWITCH TYPE SW3 (DIN)
74/122
USER GUIDE - M0SW3D1905Iv04 - V04 May 2019
•
Admin Privilege Level.
It sets the privilege level (0 to 15) of the administrator profile
(
admin
). If the privilege level received for the calling user in the affirmative answer of
the RADIUS server is equal to or more than this parameter, the user will get
administrator access (read and write access).
The parameters associated with each access option (
console
,
web access
,
telnet
,
SSH
and
FTP access
) are as follows:
•
Authentication method.
This sets whether the user validation must be made locally
or by consulting the configured tacacsplus or radius servers.
•
Fallback to local access.
When this option is enabled, if there is no accessibility to
the configured or RADIUS servers, users are permitted to validate
themselves with local user names. If the option is disabled, and the or
RADIUS servers are not accessible, users will not be granted access. Access
through the console has this option permanently enabled, for which reason it is not
configurable.
5.15
SECURITY CONFIGURATION
This menu allows traffic restrictions to be imposed, depending on the MAC addresses of
the clients. The equipment admits two modes for verifying the admitted client MAC
addresses: maclist or 802.1x.
When operating with lists, maclist, the equipment will only send traffic if the MAC address is
included in the authorized address list. Activation of the restriction and the list is configured
separately for each port.
For the 802.1x mode, the authentication of MAC addresses is done by consulting a
RADIUS server.
RADIUS
(acronym for
Remote Authentication Dial-In User Server
) is a
remote authentication protocol used to manage access to servers and communication
devices; it provides separate authentication, authorization and registration services.
The general configuration parameters for the ports are the following:
•
#.
Physical interface identifier.
•
Security Type.
It sets if the filtering service by MAC address is active in the
indicated port (
maclist
option), or the 802.1x authorization is used (
dot1x
option), or
no filter is activated (
none
option).
•
Max. Addresses.
This sets the maximum number of MAC addresses permitted at
one time in the indicated port.