Port Access Control - Advantech EKI-9516P-HV User Manual

Eki-9500 series
Table of Contents

Advertisement

4.6
Security
4.6.1

Port Access Control

In port-based authentication mode, when 802.1x is enabled globally and on the port,
successful authentication of any one supplicant attached to the port results in all
users being able to use the port without restrictions. At any given time, only one sup-
plicant is allowed to attempt authentication on a port in this mode. Ports in this mode
are under bidirectional control. This is the default authentication mode.
The 802.1X network has three components:
Authenticators: Specifies the port that is authenticated before permitting system
access.
Supplicants: Specifies host connected to the authenticated port requesting
access to the system services.
Authentication Server: Specifies the external server, for example, the RADIUS
server that performs the authentication on behalf of the authenticator, and indi-
cates whether the user is authorized to access system services.
The Port Access Control folder contains links to the following pages that allow you to
view and configure 802.1X features on the system.
4.6.1.1
Configuration
Use the Port Access Control Configuration page to enable or disable port access
control on the system.
To access this page, click Security > Port Access Control > Configuration.
Figure 4.286 Security > Port Access Control > Configuration
The following table describes the items in the previous figure.
Item
Admin Mode
VLAN Assignment
Mode
Dynamic VLAN Cre-
ation Mode
Description
The administrative mode of port-based authentication on the device.
The administrative mode of RADIUS-based VLAN assignment on the
device. When enabled, this feature allows a port to be placed into a
particular VLAN based on the result of the authentication or type of
802.1X authentication a client uses when it accesses the device. The
authentication server can provide information to the device about
which VLAN to assign the supplicant.
The administrative mode of dynamic VLAN creation on the device. If
RADIUS-assigned VLANs are enabled, the RADIUS server is
expected to include the VLAN ID in the 802.1X tunnel attributes of its
response message to the device. If dynamic VLAN creation is enabled
on the device and the RADIUS-assigned VLAN does not exist, then
the assigned VLAN is dynamically created. This implies that the client
can connect from any port and can get assigned to the appropriate
VLAN. This feature gives flexibility for clients to move around the net-
work without much additional configuration required.
259
EKI-9500 Series User Manual

Advertisement

Table of Contents
loading

Table of Contents