EasyManuals Logo

Edge-Core ECS4210-12P Web Management Guide

Edge-Core ECS4210-12P
550 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #270 background imageLoading...
Page #270 background image
Chapter 12
| Security Measures
Network Access (MAC Address Authentication)
– 270
Network Access (MAC Address Authentication)
Some devices connected to switch ports may not be able to support 802.1X
authentication due to hardware or software limitations. This is often true for
devices such as network printers, IP phones, and some wireless access points. The
switch enables network access from these devices to be controlled by
authenticating device MAC addresses with a central RADIUS server.
Note:
RADIUS authentication must be activated and configured properly for the
MAC Address authentication feature to work properly. (See “Configuring Remote
Logon Authentication Servers” on page 252.)
Note:
MAC authentication cannot be configured on trunk ports.
Command Usage
MAC address authentication controls access to the network by authenticating
the MAC address of each host that attempts to connect to a switch port. Traffic
received from a specific MAC address is forwarded by the switch only if the
source MAC address is successfully authenticated by a central RADIUS server.
While authentication for a MAC address is in progress, all traffic is blocked until
authentication is completed. On successful authentication, the RADIUS server
may optionally assign VLAN and quality of service settings for the switch port.
When enabled on a port, the authentication process sends a Password
Authentication Protocol (PAP) request to a configured RADIUS server. The user
name and password are both equal to the MAC address being authenticated.
On the RADIUS server, PAP user name and passwords must be configured in the
MAC address format XX-XX-XX-XX-XX-XX (all in upper case).
Authenticated MAC addresses are stored as dynamic entries in the switch
secure MAC address table and are removed when the aging time expires. The
maximum number of secure MAC addresses supported for the switch system is
1024.
Configured static MAC addresses are added to the secure address table when
seen on a switch port. Static addresses are treated as authenticated without
sending a request to a RADIUS server.
When port status changes to down, all MAC addresses mapped to that port are
cleared from the secure MAC address table. Static VLAN assignments are not
restored.
The RADIUS server may optionally return a VLAN identifier list to be applied to
the switch port. The following attributes need to be configured on the RADIUS
server.
Tunnel-Type = VLAN
Tunnel-Medium-Type = 802

Table of Contents

Other manuals for Edge-Core ECS4210-12P

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Edge-Core ECS4210-12P and is the answer not in the manual?

Edge-Core ECS4210-12P Specifications

General IconGeneral
BrandEdge-Core
ModelECS4210-12P
CategoryNetwork Router
LanguageEnglish

Related product manuals