Interoperability Requirements - Extreme Networks ExtremeWare 7.2e Installation And User Manual

Software version 7.2e
Table of Contents

Advertisement

Security
Add the following line to the RADIUS server dictionary file for netlogin-only enabled users:
Extreme:Extreme-Netlogin-Only = Enabled
Netlogin-Only Disabled
A netlogin-only disabled user can log in using Network Login and can also access the switch using
Telnet, SSH, or HTTP.
Add the following line to the RADIUS server dictionary file for netlogin-only disabled users:
Extreme:Extreme-Netlogin-Only = Disabled

Interoperability Requirements

For Network Login to operate, the user (supplicant) software and the authentication server must
support common authentication methods. Not all combinations provide the appropriate functionality.
Supplicant Side
On the client side, currently, the only platform that natively supports 802.1x is Windows XP, which
performs MD5 and TLS. Other 802.1x clients are available that support other operating systems and
support mixes of authentication methods.
A Windows XP 802.1x supplicant can be authenticated as a computer or as a user. Computer
authentication requires a certificate installed in the computer certificate store, and user authentication
requires a certificate installed in the individual user's certificate store.
By default, the XP machine performs computer authentication as soon as the computer is powered on,
or at link-up when no user is logged into the machine. User authentication is performed at link-up
when the user is logged in.
The XP machine can be configured to perform computer authentication at link-up even if the user is
logged in.
Any client with a web browser can interoperate using web-based authentication.
Authentication Server Side
The RADIUS server used for authentication has to be EAP-capable. Consider the following when
choosing a RADIUS server:
• The types of authentication methods supported on RADIUS, as mentioned above.
• Need to support both EAP and traditional Username-Password authentication. These are used by
Network Login and switch console login respectively.
• Need to support Vendor Specific Attributes (VSA). Some important parameters such as
Extreme-Netlogin-Vlan
Extreme-NetLogin-only
Table 30 and Table 31 show VSA definitions for both web-based network login and 802.1x network
login.
154
(destination vlan for port movement after authentication) and
(authorization for network login only) are brought back as VSAs.
ExtremeWare 7.2e Installation and User Guide

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents