EasyManua.ls Logo

D-Link DGS-3200 SERIES - Guest VLAN

D-Link DGS-3200 SERIES
287 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
DGS-3200 Series Layer 2 Gigabit Ethernet Managed Switch
121
Guest VLAN
Figure 9- 9. Guest VLAN Authentication Process
Limitations Using the Guest VLAN
1. Ports supporting Guest VLANs cannot be GVRP enabled and vice versa.
2. A port cannot be a member of a Guest VLAN and a static VLAN simultaneously.
3. Once a client has been accepted into the target VLAN, it can no longer access the Guest VLAN.
4. If a port is a member of multiple VLANs, it cannot become a member of the Guest VLAN.
In the Security folder, open the Guest VLAN folder, which will display the following window for the user to configure.
Remember, to set an 802.1X guest VLAN, the user must first configure a normal VLAN, which can be enabled here for guest
VLAN status.
Figure 9- 10. Guest VLAN window
The following fields may be modified to enable the 802.1X guest VLAN:
Parameter Description
VLAN Name
Enter the pre-configured VLAN name to create as an 802.1X guest VLAN.
Port
Set the ports to be enabled for the 802.1X guest VLAN.
Click Apply to implement the 802.1X guest VLAN settings entered. Only one VLAN may be assigned as the 802.1X guest
VLAN.
On 802.1X security-enabled networks, there is a need for non-
802.1X supported devices to gain limited access to the network,
due to lack of the proper 802.1X software or incompatible
devices, such as computers running Windows 98 or olde
r
operating systems, or the need for guests to gain access to the
network without full authorization or local authentication on the
Switch. To supplement these circumstances, this switch no
implements 802.1X Guest VLANs. These VLANs should have
limited access rights and features separate from other VLANs o
the network.
To implement 802.1X Guest VLANs, the user must first create a
VLAN on the network with limited rights and then enable it as a
802.1X guest VLAN. Then the administrator must configure the
guest accounts accessing the Switch to be placed in a Gues
VLAN when trying to access the Switch. Upon initial entry to the
Switch, the client wishing services on the Switch will need to be
authenticated by a remote RADIUS Server or local authenticatio
n
on the Switch to be placed in a fully operational VLAN. I
authenticated and the authenticator posseses the VLAN
lacement information, that client will be accepted into the full
operational target VLAN and normal switch functions will be
open to the client. If the authenticator does not have target VLAN
lacement information, the client will be returned to its
originating VLAN. Yet, if the client is denied authentication b
the authenticator, it will be placed in the Guest VLAN where i
t
has limited rights and access. The adjacent figure should give the
user a better understanding of the Guest VLAN process.

Table of Contents

Other manuals for D-Link DGS-3200 SERIES

Related product manuals