Web Management Guide

Table Of Contents
Chapter 11
| Security Measures
Configuring 802.1X Port Authentication
– 300
Configuring Port
Authenticator
Settings for 802.1X
Use the Security > Port Authentication (Configure Interface) page to configure
802.1X port settings for the switch as the local authenticator. When 802.1X is
enabled, you need to configure the parameters for the authentication process that
runs between the client and the switch (i.e., authenticator), as well as the client
identity lookup process that runs between the switch and authentication server.
Command Usage
When the switch functions as a local authenticator between supplicant devices
attached to the switch and the authentication server, configure the parameters
for the exchange of EAP messages between the authenticator and clients on
the Authenticator configuration page.
This switch can be configured to serve as the authenticator on selected ports
by setting the Control Mode to Auto on this configuration page.
Parameters
These parameters are displayed:
Port
– Port number.
Status
– Indicates if authentication is enabled or disabled on the port. The
status is disabled if the control mode is set to Force-Authorized.
Authorized
– Displays the 802.1X authorization status of connected clients.
Ye s
– Connected client is authorized.
N/A
– Connected client is not authorized, or port is not connected.
Control Mode
– Sets the authentication mode to one of the following options:
Auto
– Requires a dot1x-aware client to be authorized by the
authentication server. Clients that are not dot1x-aware will be denied
access.
Force-Authorized
– Forces the port to grant access to all clients, either
dot1x-aware or otherwise. (This is the default setting.)
Force-Unauthorized
– Forces the port to deny access to all clients, either
dot1x-aware or otherwise.
Operation Mode
– Allows single or multiple hosts (clients) to connect to an
802.1X-authorized port. (Default: Single-Host)
Single-Host
– Allows only a single host to connect to this port.
Multi-Host
– Allows multiple host to connect to this port.
In this mode, only one host connected to a port needs to pass
authentication for all other hosts to be granted network access. Similarly, a