D-Link DGS-3200-16 User Manual - Page 145

MAC-based Access Control, Notes about MAC-based Access Control

Page 145 highlights

xStack® DGS-3200 Series Layer 2 Gigabit Ethernet Managed Switch MAC-based Access Control MAC-based Access Control is a method to authenticate and authorize access using either a port or host. For port-based MAC, the method decides port access rights, while for host-based MAC, the method determines the MAC access rights. A MAC user must be authenticated before being granted access to a network. Both local authentication and remote RADIUS server authentication methods are supported. In MAC-based Access Control, MAC user information in a local database or a RADIUS server database is searched for authentication. Following the authentication result, users achieve different levels of authorization. Notes about MAC-based Access Control There are certain limitations and regulations regarding MAC-based Access Control: 1. Once this feature is enabled for a port, the Switch will clear the FDB of that port. 2. If a port is granted clearance for a MAC address in a VLAN that is not a Guest VLAN, other MAC addresses on that port must be authenticated for access and otherwise will be blocked by the Switch. 3. A port accepts a maximum of sixteen authenticated MAC addresses per physical port of a VLAN that is not a Guest VLAN. Other MAC addresses attempting authentication on a port with the maximum number of authenticated MAC addresses will be blocked. 4. Ports that have been enabled for Link Aggregation, Port Security, or GVRP authentication cannot be enabled for MAC-based Authentication. MAC-based Access Control Settings This window is used to set the parameters for the MAC-based Access Control function on the Switch. The user can set the running state, method of authentication, RADIUS password, view the Guest VLAN configuration to be associated with the MAC-based Access Control function of the Switch, and configure ports to be enabled or disabled for the MAC-based Access Control feature of the Switch. Please remember, ports enabled for certain other features, listed previously, can not be enabled for MAC-based Access Control. To view the following window, click Security > MAC-based Access Control > MAC-based Access Control Global Settings: Figure 5 - 43. MAC-based Access Control Settings window To configure a port or range of ports for the MAC-based Access Control feature, use the From Port and To Port drop-down menus to choose the ports, and then use the State drop-down menu to enable them. The following parameters may be viewed or set: 132

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273

xStack
®
DGS-3200 Series Layer 2 Gigabit Ethernet Managed Switch
132
MAC-based Access Control
MAC-based Access Control is a method to authenticate and authorize access using either a port or host. For port-based MAC, the
method decides port access rights, while for host-based MAC, the method determines the MAC access rights.
A MAC user must be authenticated before being granted access to a network. Both local authentication and remote RADIUS
server authentication methods are supported. In MAC-based Access Control, MAC user information in a local database or a
RADIUS server database is searched for authentication. Following the authentication result, users achieve different levels of
authorization.
Notes about MAC-based Access Control
There are certain limitations and regulations regarding MAC-based Access Control:
1.
Once this feature is enabled for a port, the Switch will clear the FDB of that port.
2.
If a port is granted clearance for a MAC address in a VLAN that is not a Guest VLAN, other MAC addresses on that port
must be authenticated for access and otherwise will be blocked by the Switch.
3.
A port accepts a maximum of sixteen authenticated MAC addresses per physical port of a VLAN that is not a Guest VLAN.
Other MAC addresses attempting authentication on a port with the maximum number of authenticated MAC addresses will be
blocked.
4.
Ports that have been enabled for Link Aggregation, Port Security, or GVRP authentication cannot be enabled for MAC-based
Authentication.
MAC-based Access Control Settings
This window is used to set the parameters for the MAC-based Access Control function on the Switch. The user can set the running
state, method of authentication, RADIUS password, view the Guest VLAN configuration to be associated with the MAC-based
Access Control function of the Switch, and configure ports to be enabled or disabled for the MAC-based Access Control feature
of the Switch. Please remember, ports enabled for certain other features, listed previously, can not be enabled for MAC-based
Access Control.
To view the following window, click
Security
>
MAC-based Access Control
>
MAC-based Access Control Global Settings
:
Figure 5 - 43. MAC-based Access Control Settings window
To configure a port or range of ports for the MAC-based Access Control feature, use the From Port and To Port drop-down menus
to choose the ports, and then use the State
drop-down menu to enable them. The following parameters may be viewed or set: