Dell PowerConnect 2848 User's Guide - Page 97

Admin Interface Control, Dynamic VLAN Assignment - set vlan all ports

Page 97 highlights

- None - No authentication method is used to authenticate the port. - RADIUS - Port authentication is performed using the RADIUS server. - RADIUS, None - Port authentication is performed first using the RADIUS server. If the port is not authenticated, then no authentication method is used, and the session is permitted. • Guest VLAN - Specifies whether the Guest VLAN is enabled on the device. The possible field values are: - Enable - Enables using a Guest VLAN for unauthorized ports. If a Guest VLAN is enabled, the unauthorized port automatically joins the VLAN selected in the VLAN List field. - Disable - Disables using a Guest VLAN for unauthorized ports. This is the default. • VLAN List - When Guest VLAN is enabled, this field specifies which VLAN the guest will belong to. • Interface - Contains an interface list. • User Name - The user name as configured in the RADIUS server. • Admin Interface Control - Defines the port authorization state. The possible field values are: - Auto - Enables port-based authentication on the device. The interface moves between an authorized or unauthorized state based on the authentication exchange between the device and the client. - ForceAuthorized - Indicates the interface is in an authorized state without being authenticated. The interface re-sends and receives normal traffic without client port-based authentication. - ForceUnauthorized - Denies the selected interface system access by moving the interface into unauthorized state. The device cannot provide authentication services to the client through the interface. • Current Interface Control - The currently configured port authorization state. • Authentication Type - Specifies the type of authentication on the port. The possible field values are: - 802.1x Only - Sets the authentication type to 802.1x based authentication only. - MAC Only - Sets the authentication type to MAC based authentication only. - 802.1x & MAC - Sets the authentication type to 802.1x based authentication and MAC based authentication. • Dynamic VLAN Assignment - Indicates whether dynamic VLAN assignment is enabled for this port. This feature allows network administrators to automatically assign users to VLANs during the RADIUS server authentication. When a user is authenticated by the RADIUS server, the user is automatically joined to the VLAN configured on the RADIUS server. - Port Lock and Port Monitor should be disabled when DVA is enabled. - Dynamic VLAN Assignment (DVA) can occur only if a RADIUS server is configured, and port authentication is enabled and set to 802.1x multi-session mode. - If the Radius Accept Message doesn't contain the supplicant's VLAN, the supplicant is rejected. - Authenticated ports are added to the supplicant VLAN as untagged. Update with your book title 97

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186

Update with your book title
97
None
— No authentication method is used to authenticate the port.
RADIUS
— Port authentication is performed using the RADIUS server.
RADIUS, None
— Port authentication is performed first using the RADIUS server. If the port is
not authenticated, then no authentication method is used, and the session is permitted.
Guest VLAN
— Specifies whether the Guest VLAN is enabled on the device. The possible field values
are:
Enable
— Enables using a Guest VLAN for unauthorized ports. If a Guest VLAN is enabled, the
unauthorized port automatically joins the VLAN selected in the VLAN List field.
Disable
— Disables using a Guest VLAN for unauthorized ports. This is the default.
VLAN List
— When Guest VLAN is enabled, this field specifies which VLAN the guest will belong to.
Interface
— Contains an interface list.
User Name
— The user name as configured in the RADIUS server.
Admin Interface Control
— Defines the port authorization state. The possible field values are:
Auto
— Enables port-based authentication on the device. The interface moves between an
authorized or unauthorized state based on the authentication exchange between the device and
the client.
ForceAuthorized
— Indicates the interface is in an authorized state without being authenticated.
The interface re-sends and receives normal traffic without client port-based authentication.
ForceUnauthorized
— Denies the selected interface system access by moving the interface into
unauthorized state. The device cannot provide authentication services to the client through the
interface.
Current Interface Control
— The currently configured port authorization state.
Authentication Type
— Specifies the type of authentication on the port. The possible field values are:
802.1x Only
— Sets the authentication type to 802.1x based authentication only.
MAC Only
— Sets the authentication type to MAC based authentication only.
802.1x & MAC
— Sets the authentication type to 802.1x based authentication and MAC based
authentication.
Dynamic VLAN Assignment
— Indicates whether dynamic VLAN assignment is enabled for this port.
This feature allows network administrators to automatically assign users to VLANs during the RADIUS
server authentication. When a user is authenticated by the RADIUS server, the user is automatically
joined to the VLAN configured on the RADIUS server.
Port Lock and Port Monitor should be disabled when DVA is enabled.
Dynamic VLAN Assignment (DVA) can occur only if a RADIUS server is configured, and port
authentication is enabled and set to 802.1x multi-session mode.
If the Radius Accept Message doesn’t contain the supplicant’s VLAN, the supplicant is rejected.
Authenticated ports are added to the supplicant VLAN as untagged.