Using Port-Based 802.1X - Ruckus Wireless ZoneDirector 1100 User Manual

Smart wi-fi controllers that support up to 1000 aps
Hide thumbs Also See for ZoneDirector 1100:
Table of Contents

Advertisement

Managing Access Points
Working with Access Point Groups
The following table describes the behavior of incoming and outgoing traffic for Access Ports
with VLANs configured.
Table 26. Access Ports with VLANs configured
VLAN Settings
Access Port, Untag
VLAN 1
Access Port, Untag
VLAN [2-4094]
General Ports
General ports are user-specified ports that can have any combination of up to 20 VLAN IDs
assigned. Enter multiple valid VLAN IDs separated by commas or a range separated by a
hyphen.

Using Port-Based 802.1X

802.1X authentication provides the ability to secure the network and optionally bind service
policies for an authenticated user. 802.1X provides logical port control and leverages the EAP
authentication and RADIUS protocols to allow the network policy to be effectively applied in
real time, no matter where the user connects to the network.
AP Ethernet ports can be individually configured to serve as either an 802.1X supplicant
(authenticating the AP to an upstream authenticator switch port), or as an 802.1X authenticator
(receiving 802.1X authentication requests from downstream supplicants). A single port can not
provide both supplicant and authenticator functionality at the same time.
NOTE: If mesh mode is enabled on ZoneDirector, the 802.1X port settings will be unavailable
for any APs that support mesh. The ZoneFlex 7025 does not support mesh, so 802.1X settings
will remain available for those access points even when mesh is enabled. However, the 802.1X
settings are only available from the Editing [Access Point] dialogue, not from AP Groups.
Therefore if you want to use 802.1X on ZoneFlex 7025 ports (when mesh is enabled), you must
configure each AP individually.
Incoming Traffic (from the
client)
All incoming traffic is native
VLAN (VLAN 1).
All incoming traffic is sent to the
VLANs specified.
Outgoing Traffic (to the client)
All outgoing traffic on the port is
sent untagged.
Only traffic belonging to the
specified VLAN is forwarded. All
other VLAN traffic is dropped.
164

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Zonedirector 3000Zonedirector 5000

Table of Contents