EasyManua.ls Logo

Ruijie RG-S2900G-E Series - Page 508

Ruijie RG-S2900G-E Series
943 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
Configuration Guide 802.1x Configuration
The ports connected to the access layer switches must be set as controlled ports to control the accessed users, and
the users cannot access network resources unless they first pass the authentication.
Characteristics of this solution:
The convergence layer device must be of high quality since the network is large and numerous users are connected,
since any of its fault may cause the failures of many users to normally access the network.
User management is performed on the Radius Server in a centralized manner. The administrator does not have to
know which switch a user is connected to, making management much easier.
The access layer device can be the less expensive non-NM switches (as long as they support transparent
transmission of EAPOL frames).
The administrator cannot manage the device on the access layer through the network.
Configuration
Default Configuration of 802.1x
The following table lists some defaults of the 802.1x
Item
Default
Authentication
DISABLE
Accounting
DISABLE
Radius Server
*ServerIp
*Authentication UDP port
*Key
*No default
*1812
*No default
Accounting Server
*ServerIp
*Accounting UDP port
*No default
*1813
All port types
Uncontrolled port (all ports can perform communication
directly without authentication)
Timed re-authentication
Off
Timed reauth_period
3,600 seconds
Interval between two authentication requests
10 seconds
Retransmission interval
3 seconds
Maximum retransmissions
3
Client timeout period
3 seconds, if within which no response is received from the
client, the communication is deemed as a failure
Server timeout period
5 seconds, if within which no response is received from the
server, the communication is deemed as a failure
Lists of authenticable hosts under a port
No default
Precautions for Configuring 802.1x
You can perform the following configuration only to the products that support 802.1x.
The 802.1x can run on both L2 device and L3 device.

Table of Contents

Related product manuals