D-Link DWS-1008 Product Manual - Page 292

Authentication Types, IEEE 802.1X, Last-resort, Wired authentication port

Page 292 highlights

Each authentication rule specifies where the user credentials are stored. The location can be a group of RADIUS servers or the switch's local database. In either case, if MSS has an authentication rule that matches on the required parameters, MSS checks the username or MAC address of the user and, if required, the password to make sure they match the information configured on the RADIUS servers or in the local database. The username or MAC address can be an exact match or can match a userglob or MAC address glob, which allow wildcards to be used for all or part of the username or MAC address. (For more information about globs, see "AAA Tools for Network Users".) Authentication Types MSS provides the following types of authentication: • IEEE 802.1X-If the network user's network interface card (NIC) supports 802.1X, MSS checks for an 802.1X authentication rule that matches the username (and SSID, if wireless access is requested), and that uses the Extensible Authentication Protocol (EAP) requested by the NIC. If a matching rule is found, MSS uses the requested EAP to check the RADIUS server group or local database for the username and password entered by the user. If matching information is found, MSS grants access to the user. • MAC-If the username does not match an 802.1X authentication rule, but the MAC address of the user's NIC or Voice-over-IP (VoIP) phone and the SSID (if wireless) do match a MAC authentication rule, MSS checks the RADIUS server group or local database for matching user information. If the MAC address (and password, if on a RADIUS server) matches, MSS grants access. Otherwise, MSS attempts the fallthru authentication type, which can be Web, last-resort, or none. (Fallthru authentication is described in more detail in "Authentication Algorithm".) • Web-A network user attempts to access a web page over the network. The switch intercepts the HTTP or HTTPS request and serves a login Web page to the user. The user enters the username and password, and MSS checks the RADIUS server group or local database for matching user information. If the username and password match, MSS redirects the user to the web page she requested. Otherwise, MSS denies access to the user. • Last-resort-A network user associates with an SSID or connects to a wired authentication port, and does not enter a username or password. • SSID-If 802.1X or MAC authentication do not apply to the SSID (no 802.1X or MAC access rules are configured for the SSID), the default authorization attributes set on the SSID are applied to the user and the user is allowed onto the network. • Wired authentication port-If 802.1X or MAC authentication do not apply to the port (no 802.1X or MAC access rules have the wired option set), MSS checks for user lastresort-wired. If this user is configured, the authorization attributes set for the user are applied to the user who is on the wired authentication port and the user is allowed onto the network. D-Link DWS-1008 User Manual 273

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496
  • 497
  • 498
  • 499
  • 500
  • 501
  • 502

D-Link DWS-1008 User Manual
±¶²
Each authentication rule specifies where the user credentials are stored. The location can be a group
of RADIUS servers or the switch’s local database. In either case, if MSS has an authentication rule that
matches on the required parameters, MSS checks the username or MAC address of the user and, if
required, the password to make sure they match the information configured on the RADIUS servers or
in the local database.
The username or MAC address can be an exact match or can match a userglob or MAC address glob,
which allow wildcards to be used for all or part of the username or MAC address. (For more information
about globs, see “AAA Tools for Network Users”.)
Authentication Types
MSS provides the following types of authentication:
IEEE 802.1X
—If the network user’s network interface card (NIC) supports 802.1X, MSS
checks for an 802.1X authentication rule that matches the username (and SSID, if wireless
access is requested), and that uses the Extensible Authentication Protocol (EAP) requested
by the NIC. If a matching rule is found, MSS uses the requested EAP to check the RADIUS
server group or local database for the username and password entered by the user. If
matching information is found, MSS grants access to the user.
MAC
—If the username does not match an 802.1X authentication rule, but the MAC address
of the user’s NIC or Voice-over-IP (VoIP) phone and the SSID (if wireless) do match a
MAC authentication rule, MSS checks the RADIUS server group or local database for
matching user information. If the MAC address (and password, if on a RADIUS server)
matches, MSS grants access. Otherwise, MSS attempts the fallthru authentication type,
which can be Web, last-resort, or none. (Fallthru authentication is described in more detail
in “Authentication Algorithm”.)
Web
—A network user attempts to access a web page over the network. The switch
intercepts the HTTP or HTTPS request and serves a login Web page to the user. The
user enters the username and password, and MSS checks the RADIUS server group or
local database for matching user information. If the username and password match, MSS
redirects the user to the web page she requested. Otherwise, MSS denies access to the
user.
Last-resort
—A network user associates with an SSID or connects to a wired authentication
port, and does not enter a username or password.
SSID
—If 802.1X or MAC authentication do not apply to the SSID (no 802.1X or MAC
access rules are configured for the SSID), the default authorization attributes set on the
SSID are applied to the user and the user is allowed onto the network.
Wired authentication port
—If 802.1X or MAC authentication do not apply to the port
(no 802.1X or MAC access rules have the wired option set), MSS checks for user last-
resort-wired. If this user is configured, the authorization attributes set for the user are
applied to the user who is on the wired authentication port and the user is allowed onto the
network.