Modes Of Operation; User Accounts - Extreme Networks ExtremeWare 7.2e Installation And User Manual

Software version 7.2e
Table of Contents

Advertisement

Network Login
Authentication Methods
The authentication methods supported are a matter between the supplicant and the authentication
server. The most commonly used methods are:
• MD5-Challenge.
• Transport Layer Security (TLS), which uses Public Key Infrastructure (PKI) and strong mutual
authentication.
• Tunneled TLS (TTLS), which is a Funk/Certicom proposal.
TLS represents the most secure protocol among these methods. TTLS is advertised to be as strong as
TLS. Both TLS and TTLS are certificate-based, which requires setting up a PKI that can issue, renew, and
revoke certificates. TTLS offers ease of deployment because it requires only server certificates and the
client can use the MD5 mode of username/password authentication.
For information on setting up a PKI configuration, refer to the documentation for your particular
RADIUS server and 802.1x client, if using 802.1x authentication.

Modes of Operation

Network login has two modes of operation:
• Campus mode
• ISP mode
Campus Mode
Campus mode is meant for mobile users who tend to move from one port to another and connect at
various locations in the network. In Campus mode, the authenticated port is moved from a temporary
VLAN to a permanent VLAN, which then has access to external network resources. Campus mode
requires the use of a RADIUS server as part of the authentication process.
ISP Mode
ISP mode is meant for users who will connect through the same port and VLAN each time, as though
the switch functions as an ISP. In ISP mode, the port and VLAN remain constant. Before the supplicant
is authenticated, the port is in an unauthenticated state. Once authenticated, the port will forward
packets.

User Accounts

You can create two types of user accounts for authenticating Network Login users:
• netlogin-only enabled
• netlogin-only disabled
Netlogin-Only Enabled
A netlogin-only enabled user can only log in using Network Login and cannot access the switch using
the same login.
ExtremeWare 7.2e Installation and User Guide
153

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents