How Port Based Authentication Works; Configuring 802.1X - Avaya G250 Administration

Media gateway
Hide thumbs Also See for G250:
Table of Contents

Advertisement

Accessing the Avaya G250/G350 Media Gateway

How port based authentication works

The authentication procedure is port-based, which means:
Access control is achieved by enforcing authentication on connected ports
If an endpoint station that connects to a port is not authorized, the port state is set to
"unauthorized", which closes the port to all traffic
As a result of an authentication attempt, the port can be either in a "blocked" or a
"forwarding" state
802.1x interacts with existing standards to perform its authentication operation. Specifically, it
makes use of Extensible Authentication Protocol (EAP) messages, encapsulated within
Ethernet frames (EAPOL), and EAP over RADIUS for the communication between the
Authenticator and the Authentication Server.
Note:
The G250/G350 only supports MD5 EAP type.
Note:

Configuring 802.1x

On the G350, you can configure 802.1x on the G350's PoE module (MM314). You can configure
802.1x on any of the MM314 ports except the Gigabit Ethernet port (port 51). On the G250, you
can enable 802.1x on the eight Ethernet LAN PoE ports located on the G250's front panel.
To configure 802.1x:
1. Configure RADIUS authentication on the G250/G350. For instructions, see
authentication
2. Use the set port dot1x port-control command to change the 802.1x mode of an
individual port. This command must be followed by the module and port number, and the
802.1x mode. The following are the possible modes:
- force-unauthorize — the port is always blocked
- auto — whether the port is blocked or open depends on the authentication outcome
- force-authorize — the port is always open (in forwarding state)
By default, all ports are in auto mode. In other words, all ports are configured to use 802.1x
authentication if it is enabled on the G250/G350. If a port is not in auto mode, you can use
the following command to return the port to auto mode:
G250-001(super)# set port dot1x port-control 10/4 auto
Done !
G250-001(super)#
G350-001(super)# set port dot1x port-control 6/3 auto
Done !
G350-001(super)#
48 Administration for the Avaya G250 and Avaya G350 Media Gateways
on page 46.
RADIUS

Advertisement

Table of Contents
loading

This manual is also suitable for:

G350

Table of Contents