Chapter 18 Port Authentication
XGS4600 Series User’s Guide
208
C
HAPTER
18
Port Authentication
18.1 Port Authentication Overview
This chapter describes the IEEE 802.1x, MAC, Guest VLAN, and Compound authentication methods.
Port authentication is a way to validate access to ports on the Switch to clients based on an external
authentication server. The Switch supports the following methods for port authentication:
•
IEEE 802.1x
– An authentication server validates access to a port based on a user name and
password provided by the user. A user that fails an authentication server can still access the port, but
traffic from the user is forwarded to the guest VLAN port.
•
MAC Authentication
– An authentication server validates access to a port based on the MAC address
and password of the client.
•
Guest VLAN
– In either mode, if authentication fails the Switch can still allow the client to access the
network on a
Guest VLAN
.
•
Compound Authentication
– An authentication server validates access to a port based on
combination of IEEE 802.1x and MAC Authentication. There are two modes:
•
Loose
: The client authenticates using either IEEE 802.1x authentication or MAC Authentication.
•
Strict
: The client authenticates using both IEEE 802.1x authentication and MAC Authentication.
Note: All types of authentication use the RADIUS (Remote Authentication Dial In User Service,
RFC 2138, 2139) protocol to validate users. You must configure a RADIUS server before
enabling port authentication.
Note: If you enable IEEE 802.1x authentication and MAC authentication on the same port, the
Switch performs IEEE 802.1x authentication first. If a user fails to authenticate through
the IEEE 802.1x method, then access to the port is denied.
Note: IEEE 802.1x is not supported by all user operating systems. For details on compatibility,
see your operating system documentation. If your operating system does not support
802.1x, you must install 802.1x client software.
18.1.1 What You Can Do
• Use the
Port Authentication
screen (
) to display the links to the configuration
screens where you can enable the port authentication methods.
• Use the
802.1x
screen (
) to activate IEEE 802.1x security.
• Use the
MAC Authentication
) to activate MAC authentication.
• Use the
Guest Vlan
screen (
) to enable and assign a guest VLAN to a port.
Содержание XGS4600 Series
Страница 24: ...24 PART I User s Guide ...
Страница 44: ...44 PART II Technical Reference ...
Страница 180: ...Chapter 13 Spanning Tree Protocol XGS4600 Series User s Guide 180 Figure 145 MSTP and Legacy RSTP Network Example ...
Страница 189: ...Chapter 16 Mirroring XGS4600 Series User s Guide 189 Figure 150 Advanced Application Mirroring Standalone Mode ...
Страница 244: ...Chapter 22 Policy Rule XGS4600 Series User s Guide 244 Figure 189 Policy Example EXAMPLE ...
Страница 277: ...Chapter 25 Multicast XGS4600 Series User s Guide 277 Figure 215 Advanced Application Multicast MVR Standalone Mode ...
Страница 559: ...Chapter 59 Access Control XGS4600 Series User s Guide 559 Figure 460 Example Lock Denoting a Secure Connection EXAMPLE ...
Страница 586: ...Chapter 69 Configure Clone XGS4600 Series User s Guide 586 Figure 479 Management Configure Clone Standalone Mode ...
Страница 587: ...Chapter 69 Configure Clone XGS4600 Series User s Guide 587 Figure 480 Management Configure Clone Stacking Mode ...
Страница 594: ...Chapter 71 Port Status XGS4600 Series User s Guide 594 Figure 485 Management Port Status Port Details Standalone Mode ...
Страница 604: ...604 PART III Troubleshooting and Appendices ...