Ieee802.1X Authentication Function - Fujitsu PRIMERGY 10/40GbE Connection Blade 18/8+2 Function Manual

Table of Contents

Advertisement

2.15 IEEE802.1X Authentication Function

IEEE802.1X authentication function authenticates by the RADIUS server installed externally.
This device supports authentication function (802.1X authentication) which complies with IEEE802.1X.
Authentication function corresponds to authentication methods "EAP-MD5", "EAP-TLS", "EAP-TTLS", "PEAP".
Local authentication that used AAA function within the device itself and remote authentication installed
externally by RADIUS server can be used as authentication database for executing authentication. When local
authentication is used, authentication is executed only by "EAP-MD5".
When remote authentication is used, authentication executed by "EAP-TLS" and "EAP-TTLS" which is secured as
compared to local authentication.
Communication (Authentication request is removed) of supplicant that does not have authentication
permission is entirely blocked using this function and illegal access of network from the supplicant other than
the authenticated ones is denied.
By setting the attributes to the RADIUS server Supplicant is coordinated with VLAN at the time of authentication.
When VLAN ID is not notified from RADIUS server, VID set by "ether dot1x vid" command is assigned.
RADIUS server that does operation checking in this device is Fujitsu manufactured "Safeauthor V3.5".
In this device, multiple terminals can be authenticated by 1 physical port. In such case, switching HUB etc are
connected to physical port of this device and authentication can be executed by each terminal by connecting
multiple terminals.
When multiple terminals are authenticated by 1 physical port, supplicant software that sends "EAPOL start"
message is used.
Authentication does not start in the supplicant software which does not send "EAPOL start" message.
Supplicant software which obtains operation checking in this device is a Fujitsu manufactured "Systemwalker
Desktop Inspection 802.1X supplicant".
Points to be noted
 VLAN cannot be set in advance, in the port used by this device. Terminal with successful authentication
communicates with VLAN assigned when authentication is successful.
Page 36 of 71

Advertisement

Table of Contents
loading

Table of Contents