EasyManuals Logo

SNR S2940-8G-v2 User Manual

SNR S2940-8G-v2
420 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #314 background imageLoading...
Page #314 background image
SNR S2940-8G-v2 Switch Configuration Guide
802.1x Configuration
Supplicant
PAE
Authenticator
System PAE
RADIUS
server
EAPOL-Start
EAP-Request/Identity
EAP-Response/Identity
RADIUS Access-Request
(EAP-Response/Identity)
EAP-Request/PEAP Start
RADIUS Access-Challenge
(EAP-Request/PEAP Start)
EAP-Response(Empty)
RADIUS Access-Request
EAP-Response(Empty)
EAP-Request/MD5 Challenge
RADIUS Access-Challenge
(EAP-Request/MD5 Challenge)
EAPOL EAPOR
TLS Channel Established
...
...
EAP-Response/MD5 Password
RADIUS Access-Request
(EAP-Response/MD5 Password)
EAP-Success
RADIUS Access-Accept
(EAP-Success)
Figure 45.11: the Authentication Flow of 802.1x PEAP
this method: standard control and advanced control. The user-based standard control
will not restrict the access to limited resources, which means all users of this port can
access limited resources before being authenticated. The user-based advanced con-
trol will restrict the access to limited resources, only some particular users of the port
can access limited resources before being authenticated. Once those users pass the
authentication, they can access all resources.
Attention: when using private supplicant systems, user-based advanced control is recom-
mended to effectively prevent ARP cheat.
For the maximum number of the authenticated users, the maximum number of IPv4 users
supported by user-based is 400, the maximum number of IPv6 users supported by user-based is
800. mac-based relates to ratelimit value of switch, it can supports 4000 authenticated users, but
it is recommended that the number of the authenticated users should not exceed 2000.
45.1.7 The Features of VLAN Allocation
1. Auto VLAN
Auto VLAN feature enables RADIUS server to change the VLAN to which the access port be-
longs, based on the user information and the user access device information. When an 802.1x
user passes authentication on the server, the RADIUS server will send the authorization infor-
mation to the device, if the RADIUS server has enabled the VLAN-assigning function, then the
following attributes should be included in the Access-Accept messages:
• Tunnel-Type = VLAN (13)
314

Table of Contents

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the SNR S2940-8G-v2 and is the answer not in the manual?

SNR S2940-8G-v2 Specifications

General IconGeneral
BrandSNR
ModelS2940-8G-v2
CategorySwitch
LanguageEnglish