D-Link DGS-3120-24TC Product Manual - Page 232

Compound Authentication Guest VLAN Settings (EI Mode Only)

Page 232 highlights

xStack® DGS-3120 Series Managed Switch Web UI Reference Guide Parameter Description Authorization Network State Click the radio buttons to enable of disable the Authorization Network State. Authentication Server Failover Click the radio buttons to configure the authentication server failover function. Local. The switch will resort to using the local database to authenticate the client. If the client fails on local authentication, the client is regarded as unauthenticated, otherwise, it authenticated. Permit. The client is always regarded as authenticated. If guest VLAN is enabled, clients will stay on the guest VLAN, otherwise, they will stay on the original VLAN. Block (default setting). The client is always regarded as un-authenticated. Unit Select the unit you want to configure. From Port Use this drop-down menu to select the beginning port of a range of ports to be enabled as compound authentication ports. To Port Use this drop-down menu to select the ending port of a range of ports to be enabled as compound authentication ports. Authentication Methods (EI Mode Only) The compound authentication method options include: None, Any (MAC, 802.1X or WAC), 802.1X+IMPB, IMPB+WAC, and MAC+IMPB. None - all compound authentication methods are disabled. Any (MAC, 802.1X or WAC) - if any of the authentication methods pass, then access will be granted. In this mode, MAC, 802.1X and WAC can be enabled on a port at the same time. In Any (MAC, 802.1X or WAC) mode, whether an individual security module is active on a port depends on its system state. 802.1X+IMPB - 802.1X will be verified first, and then IMPB will be verified. Both authentication methods need to be passed. IMPB+WAC - IMPB will be verified first, and then WAC will be verified. Both authentication methods need to be passed. MAC+IMPB - MAC will be verified first, and then IMPB will be verified. Both authentication methods need to be passed. Authorized Mode Toggle between Host-based and Port-based. When Port-based is selected, if one of the attached hosts passes the authentication, all hosts on the same port will be granted access to the network. If the user fails the authorization, this port will keep trying the next authentication method. When Host-based is selected, users are authenticated individually. VID List Enter a list of VLAN ID. State Use the drop-down menu to assign or remove the specified VID list as authentication VLAN(s). Click the Apply button to accept the changes made for each individual section. Compound Authentication Guest VLAN Settings (EI Mode Only) Users can assign ports to or remove ports from a guest VLAN. To view this window, click Security > Compound Authentication > Compound Authentication Guest VLAN Settings as shown below: 224

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339

xStackĀ® DGS-3120 Series Managed Switch Web UI Reference Guide
224
Parameter
Description
Authorization Network State
Click the radio buttons to enable of disable the Authorization Network State.
Authentication Server
Failover
Click the radio buttons to configure the authentication server failover function.
Local
. The switch will resort to using the local database to authenticate the
client. If the client fails on local authentication, the client is regarded as un-
authenticated, otherwise, it authenticated.
Permit
. The client is always regarded as authenticated. If guest VLAN is
enabled, clients will stay on the guest VLAN, otherwise, they will stay on the
original VLAN.
Block
(default setting). The client is always regarded as un-authenticated.
Unit
Select the unit you want to configure.
From Port
Use this drop-down menu to select the beginning port of a range of ports to
be enabled as compound authentication ports.
To Port
Use this drop-down menu to select the ending port of a range of ports to be
enabled as compound authentication ports.
Authentication Methods (EI
Mode Only)
The compound authentication method options include: None, Any (MAC,
802.1X or WAC), 802.1X+IMPB, IMPB+WAC, and MAC+IMPB.
None
- all compound authentication methods are disabled.
Any (MAC, 802.1X or WAC)
- if any of the authentication methods pass, then
access will be granted. In this mode, MAC, 802.1X and WAC can be enabled
on a port at the same time. In Any (MAC, 802.1X or WAC) mode, whether an
individual security module is active on a port depends on its system state.
802.1X+IMPB
- 802.1X will be verified first, and then IMPB will be verified.
Both authentication methods need to be passed.
IMPB+WAC
- IMPB will be verified first, and then WAC will be verified. Both
authentication methods need to be passed.
MAC+IMPB
- MAC will be verified first, and then IMPB will be verified. Both
authentication methods need to be passed.
Authorized Mode
Toggle between
Host-based
and
Port-based
. When
Port-based
is selected, if
one of the attached hosts passes the authentication, all hosts on the same
port will be granted access to the network. If the user fails the authorization,
this port will keep trying the next authentication method. When
Host-based
is
selected, users are authenticated individually.
VID List
Enter a list of VLAN ID.
State
Use the drop-down menu to assign or remove the specified VID list as
authentication VLAN(s).
Click the
Apply
button to accept the changes made for each individual section.
Compound Authentication Guest VLAN Settings (EI Mode
Only)
Users can assign ports to or remove ports from a guest VLAN.
To view this window, click
Security > Compound Authentication > Compound Authentication Guest VLAN
Settings
as shown below: