Siemens SCALANCE XB-200 Configuration Manual page 243

Industrial ethernet switches
Hide thumbs Also See for SCALANCE XB-200:
Table of Contents

Advertisement

Local logon
The local logging on of users by the device runs as follows:
1. The user logs on with user name and password on the device.
2. The device checks whether an entry exists for the user.
→ If an entry exists, the user is logged in with the rights of the associated role.
→ If no corresponding entry exists, the user is denied access.
Login via an external RADIUS server
RADIUS(Remote Authentication Dial-In User Service) is a protocol for authenticating and
authorizing users by servers on which user data can be stored centrally.
The authentication of users via a RADIUS server is as follows:
1. The user logs on with user name and password on the device.
2. The device sends an authentication request with the login data to the RADIUS server.
3. The RADIUS server runs a check and signals the result back to the device.
– The RADIUS server reports a successful authentication and for the "Service Type"
– The RADIUS server reports a successful authentication and returns a different or even
– The RADIUS server reports a failed authentication to the device:
Assignment of a VLAN via RADIUS or guest VLAN in Base Bridge mode "802.1Q VLAN Bridge"
Authentication with a change to the VLAN configuration
If during authentication a port is assigned to a VLAN dynamically using the function "RADIUS
VLAN Assignment Allowed" or "Guest VLAN" the options are as follows:
● If the VLAN that is to be assigned has not been created on the device, the authentication
is rejected.
● If the VLAN that is to be assigned has been created on the device:
– The port becomes an untagged member in the assigned VLAN if it was not already.
– The port VID of the port is changed to the ID of the assigned VLAN.
Note
If the port is only to be assigned to one VLAN, you need to adapt the VLAN configuration
manually. As default, all ports are untagged members in "VLAN 1".
SCALANCE XB-200/XC-200/XP-200 Web Based Management
Configuration Manual, 07/2016, C79000-G8976-C360-04
attribute returns the value "Administrative User" to the device
→ The user is logged in with read/write rights.
no value to the device for the attribute "Service Type".
→ The user is logged in with read rights.
→ The user is denied access.
→ This makes it possible for the static configuration of the port in this VLAN to be
overwritten and not restored if the authentication is retracted.
Configuring with Web Based Management
5.7 The "Security" menu
243

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Scalance xc-200Scalance xp-200

Table of Contents