3Com 3C17300A Implementation Guide - Page 82

What is Rada?, How Rada Works

Page 82 highlights

82 CHAPTER 10: MAKING YOUR NETWORK SECURE For Network Login, the Switch uses EAP (Extensible Authentication Protocol). For further information about RADIUS, see "What is RADIUS?" on page 85. What is Rada? The Radius Authenticated Device Access feature complements the existing 802.1X support of the Switch. Instead of needing an 802.1X client on every end station, the switch can use the MAC address of the end station to query the RADIUS server. How Rada Works The Rada feature controls the network access of a host based on authenticating its MAC address. A host is allowed access to the entire network, to a restricted network or no access at all. The switch obtains the network access authorisation from a centrally located RADIUS server by supplying the MAC address of the host as shown in Figure 20 Figure 20 Network Login Operation via MAC Address Network Access Client without 802.1x (Client Device) Network Access Server (Switch 4200) MAC address Authentication via MAC Address RADIUS Server For Rada, the Switch uses PAP (Password Authentication Protocol). Rada has an 'Unauthorized Device action' of allowDefaultAccess or blockMacAddress, which control the action on authentication refusal.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122

82
C
HAPTER
10: M
AKING
Y
OUR
N
ETWORK
S
ECURE
For Network Login, the Switch uses EAP (Extensible Authentication
Protocol).
For further information about RADIUS, see
“What is RADIUS?”
on
page 85
.
What is Rada?
The Radius Authenticated Device Access feature complements the
existing 802.1X support of the Switch. Instead of needing an 802.1X
client on every end station, the switch can use the MAC address of the
end station to query the RADIUS server.
How Rada Works
The Rada feature controls the network access of a host based on
authenticating its MAC address. A host is allowed access to the entire
network, to a restricted network or no access at all. The switch obtains
the network access authorisation from a centrally located RADIUS server
by supplying the MAC address of the host as shown in
Figure 20
Figure 20
Network Login Operation via MAC Address
For Rada, the Switch uses PAP (Password Authentication Protocol).
Rada has an ‘Unauthorized Device action’ of allowDefaultAccess or
blockMacAddress, which control the action on authentication refusal.
Network Access Server
(Switch 4200)
Network Access Client without 802.1x
(Client Device)
MAC address
Authentication
via MAC Address
RADIUS Server