GS2220 Series User’s Guide
201
18.6 Co m po und Authe ntic a tio n
Use this screen to allow network access for clients that:
• pass either IEEE 802.1x authentication OR MAC authentication, or
• pass both IEEE 802.1x authentication AND MAC authentication.
The authentication modes are:
• In IEEE 802.1x authentication, the Switch prompts the client for login information in the form of a user
name and password. When the client provides the login credentials, the Switch sends an
authentication request to a RADIUS server. The RADIUS server validates whether this client is allowed
access to the port. Use the AAA > RADIUS Se rve r Se tup screen to configure the RADIUS server.
• In MAC authentication, the login credentials are based on the source MAC address of the client
connecting to a port on the Switch along with a password configured specifically for MAC
authentication on the Switch.
In the Port Authe ntic a tio n screen click C o m po und Authe ntic a tio n Mo de to display the configuration
screen as shown.
Active Select this check box to enable the guest VLAN feature on this port.
Clients that fail authentication are placed in the guest VLAN and can receive limited services.
Guest Vlan A guest VLAN is a pre-configured VLAN on the Switch that allows non-authenticated users to
access limited network resources through the Switch. You must also enable IEEE 802.1x
authentication on the Switch and the associated ports. Enter the number that identifies the
guest VLAN.
Make sure this is a VLAN recognized in your network.
Host-mode Specify how the Switch authenticates users when more than one user connect to the port
(using a hub).
Select Multi- Ho st to authenticate only the first user that connects to this port. If the first user
enters the correct credential, any other users are allowed to access the port without
authentication. If the first user fails to enter the correct credential, they are all put in the guest
VLAN. Once the first user who did authentication logs out or disconnects from the port, the rest
of the users are blocked until a user does the authentication process again.
Select Multi- Se c ure to authenticate each user that connects to this port.
Multi-Secure Num If you set Ho st- mo de to Multi- Se c ure , specify the maximum number of users (between 1 and 5)
that the Switch will authenticate on this port.
Apply Click App ly to save your changes to the Switch’s run-time memory. The Switch loses these
changes if it is turned off or loses power, so use the Sa ve link on the top navigation panel to
save your changes to the non-volatile memory when you are done configuring.
Cancel Click Ca nc e l to begin configuring this screen afresh.
Table 83 Advanced Application > Port Authentication > Guest VLAN (continued)
LABEL DESCRIPTIO N