Configuration; Configuration Task List - Digitalchina Networks DCS-3950 series Manual

Table of Contents

Advertisement

authenticating packets. A managed port will be in the connected status when authorized to
transfer commutation packets; and is shutdown when not authorized, and cannot transfer
any packets.
In the IEEE 802.1x application environment, DCS-3950 series is used as the access
management unit, and the user connection device is the device with 802.1x client
software. An authenticating server usually resides in the Carrier's AAA center and usually
is a Radius server.
The difference between user access, MAC-based IEEE 802.1x authentication is
implemented in DCS-3950 series for better security and management. Only authenticated
user access devices connecting to the same physical port can access the network, the
unauthorized devices will not be able to access the network. In this way, even if multiple
terminals are connected via one physical port, DCS-3950 series can still authenticate and
manage each user access device individually.
User-based (IP address+ MAC address+ port) 802.1x authentication function is
implemented on the base of MAC-based 802.1x authentication function, allowing users to
access restricted resources before being authenticated. For user-based access control
mode, there are two modes: standard control and advanced control. User-based standard
control type does not limit the access to restricted resources, all the users of the port can
access restricted resources before being authenticated, and after being authenticated,
users can access all the resources; while the user-based advanced control will limit the
access to restricted resources, only special users of the port can access restricted resorce
before being authenticated, after passing the authentication, they can access all the
resources.
14.2 802.1x Configuration
14.2.1 802.1x Configuration Task List
1. Enable IEEE 802.1x function
2. Access management unit property configuration
1) Configure port authentication status
2) Configure access management method for the port: MAC-based or port-based.
3) Configure expanded 802.1x function
3. User access devices related property configuration (optional)
4. RADIUS server related property configuration
1) Configure RADIUS authentication key.
2) Configure RADIUS Server
3) Configure RADIUS Service parameters.
1. Enable 802.1x function
Command
DCS-3950 series Ethernet switch manual
Explanation
224

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents