Nac Features Supported By The S3700; Configuring Web Authentication; Establishing The Configuration Task - Huawei Quidway S3700 Series Configuration Manual

Hide thumbs Also See for Quidway S3700 Series:
Table of Contents

Advertisement

Quidway S3700 Series Ethernet Switches
Configuration Guide - Security

2.2 NAC Features Supported by the S3700

This section describes the NAC features supported by the S3700.
Functioning as the network access device (NAD), the S3700 supports the following NAC
features:
l
l
l
l
l
l
l
l
l
l

2.3 Configuring Web Authentication

This section describes how to configure the Web authentication function.

2.3.1 Establishing the Configuration Task

Applicable Environment
The Web authentication can be configured for users who cannot install client software. Such
users can enter the user names and passwords in the Internet Web Browser for authentication.
Issue 01 (2011-07-15)
Interface-based 802.1x authentication
MAC address-based 802.1x authentication
EAPOL termination authentication
EAPOL transparent transmission authentication
MAC address authentication
MAC address bypass authentication
The S3700 automatically specifies the VLAN for users after users pass 802.1x
authentication, MAC address authentication, or MAC address bypass authentication.
When passing 802.1x authentication, MAC address authentication, or MAC bypass
authentication, the system delivers a VLAN to the user according to the VLAN information
carried in response packets of the authentication server in either of the following modes:
– If the VLAN ID carried in response packets of the authentication server is an integer
ranging from 1 to 4094, the system delivers the VLAN according to the VLAN ID.
– If the VLAN ID carried in response packets of the authentication server is not an integer
ranging from 1 to 4094, the system delivers the VLAN according to the VLAN
description.
After users pass 802.1x authentication, MAC address authentication, or MAC address
bypass authentication, the S3700 automatically delivers ACLs to users to allow user packets
to pass through by default.
Web authentication
Authorization ACL dynamically delivered by RADIUS server
If a RADIUS server is configured to deliver authorization ACL and RADIUS scheme is
configured on the related interface of the S3700, then the S3700 controls user access
permission according to the authorization ACL delivered by the RADIUS server. The
network administrator can modify the access permission of a user by changing the
authorization ACL configuration on the RADIUS server or the ACL rules on the S3700.
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
2 NAC Configuration
50

Advertisement

Table of Contents
loading

Table of Contents