Page 91 / 216 Scroll up to view Page 86 - 90
D-Link DES-6500 Layer 3 Stackable Gigabit Ethernet Switch
73
Figure 4- 41. Typical 802.1X Configuration with User Authentication
The user’s information, including account number, password, and configuration details such
as IP address and billing information, is stored in a centralized RADIUS server.
Figure 4- 42.
Typical Configuration with 802.1X Fully Implemented
Page 92 / 216
D-Link DES-6500 Layer 3 Stackable Gigabit Ethernet Switch
74
Port Timers state machine
Authenticator PAE state machine
The Authenticator Key Transmit state machine
Reauthentication Timer state machine
Backend Authentication state machine
Controlled Directions state machine
The Key Receive state machine
Conformance to IEEE 802.1X Standards
Configure Authenticator
To display the current
802.1X Authenticator Settings
on the switch, open the
Configuration
folder, and then the
Port Access Entity
folder and finally click on the
Configure
Authenticator
link. This will open the
802.1X Authenticator Settings
page, as shown
below.
Figure 4- 43. 802.1x Authenticator Settings window
To configure the
802.1X Authenticator Settings
for a given port, click on the blue port
number under the
Port
heading. This will open the
802.1X Authenticator Settings
page, as
shown below.
Page 93 / 216
D-Link DES-6500 Layer 3 Stackable Gigabit Ethernet Switch
75
Figure 4- 44. 802.1x Authenticator Settings modify window
This window allows you to set the following features:
Parameter
Description
Unit
Allows you to select a switch from a switch stack using that switch’s Unit ID.
From [
] To [
]
Enter the port or ports to be set.
AdmDir
From the pull-down menu, select whether a controlled Port that is
unauthorized will exert control over communication in both (
both
) receiving
and transmitting directions, or just the receiving direction (
in
). The default is
both
.
Port Control
Displays the administrative control over the port’s authorization status.
forceAuthorized
forces the Authenticator of the port to become Authorized.
forceUnauthorized
forces the port to become Unauthorized.
Auto
means the
port state reflects the outcome of the authentication exchange between
supplicant, authenticator, and authentication. The default is
forceAuthorized.
TxPeriod
Select the time to wait for a response from a supplicant (user) to send EAP
Request/Identity packets. The default is 30 seconds.
Quiet Period
Select the time interval between authentication failure and the start of a new
authentication attempt. The default is 60 seconds.
SuppTimeout
Select the time to wait for a response from a supplicant (user) for all EAP
packets, except for the Request/Identity packets. The default is 30 seconds
Page 94 / 216
D-Link DES-6500 Layer 3 Stackable Gigabit Ethernet Switch
76
Server Timeout
Select the length of time to wait for a response from a RADIUS server. The
default is 30 seconds.
Max Req
Select the maximum number of times to retry sending packets to the
supplicant. The default is 2.
ReAuthPeriod
Select the time interval between successive re-authentications. The default is
3600 seconds.
ReAuth
Enable or disable reauthentication. The default is Disabled.
Configuring Local Users
In the configuration folder, open the
Port Access Entity
folder and click
Local users
to open
the
802.1x Local User Table Configuration
window. This window will allow the user to set
different local users on the Switch.
Figure 4- 45. 802.1x Local User Table Configuration window
Enter a
User Name
,
Password
and confirmation of that password. Properly configured local
users will be displayed in the
802.1x Local Users Table
in the same window.
PAE System Control
Port Capability Settings
Existing 802.1x port settings are displayed and can be configured using the window below.
Click
Port Capability Settings
on the
PAE Access Entity
folder on the
Configuration
menu
to open the
802.1X Capability Settings
window
:
Page 95 / 216
D-Link DES-6500 Layer 3 Stackable Gigabit Ethernet Switch
77
Figure 4- 46. 802.1x Capability Settings and Table window
To set up the switch’s 802.1x port-based authentication, select which ports are to be
configured in the From
and
To
fields. Next, enable the ports by selecting
Authenticator
from
the drop-down menu under Capability. Click
Apply
to let your change take effect.
Configure the following 802.1x capability settings:
Parameter
Description
Unit
Allows you to select a switch from a switch stack using that switch’s Unit ID.
From
and
To
Ports being configured for 802.1x settings.
Capability
Two role choices can be selected:
Authenticator
A user must pass the authentication process to gain access
to the network.
None
The port is not controlled by the 802.1x functions.
Initializing Ports
Existing 802.1x port settings are displayed and can be configured using the window below.
Click
Initialize Port(s)
on the
PAE Access Entity
folder on the
Configuration
menu to open
the
802.1x Port Initial
window:

Rate

3.5 / 5 based on 2 votes.

Bookmark Our Site

Press Ctrl + D to add this site to your favorites!

Share
Top