D-Link DGS-3200-16 User Manual - Page 159

Authorization Network State Settings, Multiple Authentication Settings

Page 159 highlights

xStack® DGS-3200 Series Layer 2 Gigabit Ethernet Managed Switch This mode adds an extra layer of security by checking the IP MAC-Binding Port Binding (IMPB) table before trying one of the supported authentication methods. The IMPB Table is used to create a 'white-list' that checks if the IP streams being sent by authorized hosts have been granted or not. In the above diagram, the Switch port has been configured to allow clients to authenticate using either WAC or JWAC. If the client is in the IMPB table and tries to connect to the network using either of these supported authentication methods and the client is listed in the white list for legal IP/MAC/port checking, access will be granted. If a client fails one of the authentication methods, access will be denied. The Multiple Authentication folder contains three windows: Authorization Network State Settings, Multiple Authentication Settings, and Guest VLAN Settings. Authorization Network State Settings Users can configure Authorization Network State Settings for the Switch. To view the following window, click Security > Multiple Authentication > Authorization Network State Settings: Figure 5 - 58. Authorization Network State Settings window Multiple Authentication Settings Users can configure multiple authentication methods for a port or ports. To view the following window, click Security > Multiple Authentication > Multiple Authentication Settings: Figure 5 - 59. Multiple Authentication Settings window To set up multiple authentication on individual ports for the Switch, complete the following fields: Parameter Description From Port To Port Methods Use this drop-down menu to select the beginning port of a range of ports to be enabled as multiple authentication ports. Use this drop-down menu to select the ending port of a range of ports to be enabled as multiple authentication ports. The multiple authentication method options include: None, Any (MAC, 802.1X or WAC/JWAC), 802.1X+IMPB, IMPB+JWAC, and IMPB+WAC. y None means all multiple authentication methods are disabled. y Any (MAC, 802.1X or WAC/JWAC) means if any of the authentication methods pass, then access will be granted. In this mode, MBAC, 802.1X and WAC/JWAC) 146

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273

xStack
®
DGS-3200 Series Layer 2 Gigabit Ethernet Managed Switch
146
This mode adds an extra layer of security by checking the IP MAC-Binding Port Binding (IMPB) table before trying one of the
supported authentication methods. The IMPB Table is used to create a ‘white-list’ that checks if the IP streams being sent by
authorized hosts have been granted or not. In the above diagram, the Switch port has been configured to allow clients to
authenticate using either WAC or JWAC. If the client is in the IMPB table and tries to connect to the network using either of these
supported authentication methods and the client is listed in the white list for legal IP/MAC/port checking, access will be granted.
If a client fails one of the authentication methods, access will be denied.
The
Multiple Authentication
folder contains three windows:
Authorization Network State Settings
,
Multiple Authentication
Settings
, and
Guest VLAN Settings
.
Authorization Network State Settings
Users can configure Authorization Network State Settings for the Switch.
To view the following window, click
Security > Multiple Authentication > Authorization Network State Settings
:
Figure 5 - 58. Authorization Network State Settings window
Multiple Authentication Settings
Users can configure multiple authentication methods for a port or ports.
To view the following window, click
Security > Multiple Authentication > Multiple Authentication Settings
:
Figure 5 - 59. Multiple Authentication Settings window
To set up multiple authentication on individual ports for the Switch, complete the following fields:
Parameter
Description
From Port
Use this drop-down menu to select the beginning port of a range of ports to be enabled as
multiple authentication ports.
To Port
Use this drop-down menu to select the ending port of a range of ports to be enabled as
multiple authentication ports.
Methods
The multiple authentication method options include:
None
,
Any (MAC, 802.1X or
WAC/JWAC)
,
802.1X+IMPB
,
IMPB+JWAC
, and
IMPB+WAC
.
y
None
means all multiple authentication methods are disabled.
y
Any (MAC, 802.1X or WAC/JWAC)
means if any of the authentication methods
pass, then access will be granted. In this mode, MBAC, 802.1X and WAC/JWAC)