D-Link DES-3028 Product Manual - Page 119

IGMP Authentication, Framed-IP-Address, User-Name, User-Password - default ip address

Page 119 highlights

DES-3028 DES-3028P DES-3028G DES-3052 DES-3052P Layer 2 Fast Ethernet Managed Switch IGMP Authentication IGMP Access Authentication provides a client-server authentication protocol for specified ports on the Switch. This function will secure access to an IP multicast group by using a user authentication process that will insure there is more control over the access to multicast traffic. Only the host/port that passes the authentication process can successfully join the multicast group and receive multicast data. When a host sends a join message for the interested multicast group, the switch has to authenticate the request first before learning the multicast group/port. To do this the switch sends an access-request to the authentication server for information about the host MAC address, switch port number, the switch IP and the multicast group IP. When an access-accept request is answered from the authentication server the switch learns the multicast group. If an access-reject request is answered from the authentication server, the switch will not learn the multicast group/port and will not process the packet any further. The entry will then be put on the authentication failed list. If there is no answer from the authentication server after a specific period of time the switch will resend the access-request to the server. If the switch doesn't receive any response after a specific number of times, the request is denied and the entry is entered into the authentication failed list. When the multicast group/port is already learned by the switch, it will not do the authentication again. NOTE: Attribute name Type Description User-Name string MAC-address of the computer, which will send the IGMPreport/IGMP-leave packet. User-Password string The password of the user to be authenticated. NAS-Port NAS-IP-Address Framed-IP-Address integer string string The switch port number. The switch IP-address. The multicast group IP, that makes the join/leave attempt. 1. In RFC2865, the attribute Framed-IP-Address indicates that the NAS should use that value as the user's IP address. In this function, we use that value as the multicast group IP address. 2. The attribute User-Name indicates the host's MAC-address in the format 000102030405. 3. The attribute User-Password indicates the password to be authenticated. The vaule is the same as User-Name by default This function allows the user to select a range of ports that will be included in the forwarding task and enable or disable their state. To view this window click L2 Features > IGMP Snooping > IGMP Access Control. 105

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333

DES-3028 DES-3028P DES-3028G DES-3052 DES-3052P Layer 2 Fast Ethernet Managed Switch
IGMP Authentication
IGMP Access Authentication provides a client-server authentication protocol for specified ports on the Switch. This function will
secure access to an IP multicast group by using a user authentication process that will insure there is more control over the access
to multicast traffic. Only the host/port that passes the authentication process can successfully join the multicast group and receive
multicast data.
When a host sends a join message for the interested multicast group, the switch has to authenticate the request first before learning
the multicast group/port. To do this the switch sends an access-request to the authentication server for information about the host
MAC address, switch port number, the switch IP and the multicast group IP. When an access-accept request is answered from the
authentication server the switch learns the multicast group. If an access-reject request is answered from the authentication server,
the switch will not learn the multicast group/port and will not process the packet any further. The entry will then be put on the
authentication failed list. If there is no answer from the authentication server after a specific period of time the switch will resend
the access-request to the server. If the switch doesn’t receive any response after a specific number of times, the request is denied
and the entry is entered into the authentication failed list. When the multicast group/port is already learned by the switch, it will
not do the authentication again.
NOTE:
Attribute name
Type
Description
User-Name
string
MAC-address of the computer, which will send the IGMP-
report/IGMP-leave packet.
User-Password
string
The password of the user to be authenticated.
NAS-Port
integer
The switch port number.
NAS-IP-Address
string
The switch IP-address.
Framed-IP-Address
string
The multicast group IP, that makes the join/leave attempt.
1. In RFC2865, the attribute
Framed-IP-Address
indicates that the NAS should use that value as the
user’s IP address. In this function, we use that value as the multicast group IP address.
2. The attribute
User-Name
indicates the host’s MAC-address in the format 000102030405.
3. The attribute
User-Password
indicates the password to be authenticated. The vaule is the same as
User-Name
by default
This function allows the user to select a range of ports that will be included in the forwarding task and enable or disable their state.
To view this window click
L2 Features
>
IGMP Snooping > IGMP Access Control
.
105