This solution is described as below:
Requirements of this solution:
1. The user supports 802.1X. That is, it is installed with the 802.1X client (Windows
XP carried, Star-supplicant or other IEEE802.1X-compliant client software).
2. The access layer device supports IEEE 802.1X.
3. One or multiple RADIUS-compliant servers are available as the authentication
server.
Key points for configuration of this solution:
1. The ports connected to the Radius Server and the uplink ports are configured as
uncontrolled ports, so that the device can normally communicate with the server
and the authorized users can access network resources through the uplink
interface.
2. The ports connected to the user must be set to controlled ports, to control the
accessed users, and the users cannot access network resources unless they first
pass the authentication.
Characteristics of this solution:
1. Each 802.1X-enabled device is responsible for a small number of clients, thus
offering higher speed.The devices are mutually independent, and the restart
operation of the device does not affect the users connected with other devices.
2. User management is performed on the Radius Server in a centralized manner. The
administrator does not have to know which device a user is connected to, making
management much easier.
3. The administrator can manage the device on the access layer through the network.