XGS-5240-Series User Manual

Table Of Contents
Configuration Guide of XGS-5240-Series
56-1
Chapter 56 MAB Configuration
56.1 Introduction to MAB
In actual network existing the device which can not install the authentication client,
such as printer, PDA devices, they can not process 802.1x authentication. However, to
access the network resources, they need to use MAB authentication to replace 802.1x
authentication.
MAB authentication is a network accessing authentication method based on the ac
cessing port and the MAC address of MAB user. The user neednt install any authentic
ation client, after the authentication device receives ARP packets sent by MAB user, it
will authenticate the MAC address of the MAB user and there is the corresponding aut
hentication information in the authentication server, the matched packets of the port and
the source MAC are allowed to pass when the authentication is successful. MAB user
didnt need to input the username and password manually in the process of authentica
tion.
At present, MAB authentication device only supports RADIUS authentication method.
There is the selection method for the authentication username and password: use the
MAC address of the MAB user as the username and password, or the fixed username
and password (all users use the configured username and password to authenticate).
56.2 MAB Configuration Task List
MAB Configuration Task List:
1. Enable MAB function
1) Enable global MAB function
2) Enable port MAB function
2. Configure MAB authentication username and password
3. Configure MAB parameters
1) Configure guest-vlan
2) Configure the binding-limit of the port
3) Configure the reauthentication time
4) Configure the offline detection time
5) Configure other parameters
1. Enable MAB function