3Com 3848 Implementation Guide - Page 80

Important Considerations, This contains some important considerations when using Network

Page 80 highlights

80 CHAPTER 10: MAKING YOUR NETWORK SECURE Figure 18 Network Login Operation Network Access Client (Client Device) Authentication Information Network Access Server (Switch 3848) Authentication Information RADIUS Server When the client device and RADIUS server have exchanged authentication information, the Switch receives either an authentication succeeded or failed message from the server, and then configures the port to forward or filter traffic as appropriate. If access is granted, the Spanning Tree Protocol places the port into the forwarding state and the client device can obtain an IP address. If possible, when a port is configured for Network Login, it should also be configured to be a Spanning Tree Protocol (STP) edge port. This minimizes the delay before STP places the port into the forwarding state. For further information about RADIUS, see "What is RADIUS?" on page 83. Important Considerations This section contains some important considerations when using Network Login on your Switch. ■ Before you enable Network Login you must ensure that: ■ RADIUS has been configured on the Switch. ■ The RADIUS server in your network is operational. ■ If the RADIUS server fails or is unavailable, client devices will be unable to access the network.

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110

80
C
HAPTER
10: M
AKING
Y
OUR
N
ETWORK
S
ECURE
Figure 18
Network Login Operation
When the client device and RADIUS server have exchanged
authentication information, the Switch receives either an authentication
succeeded or failed message from the server, and then configures the
port to forward or filter traffic as appropriate. If access is granted, the
Spanning Tree Protocol places the port into the forwarding state and the
client device can obtain an IP address.
If possible, when a port is configured for Network Login, it should also be
configured to be a Spanning Tree Protocol (STP) edge port. This minimizes
the delay before STP places the port into the forwarding state.
For further information about RADIUS, see
What is RADIUS?
on
page 83
.
Important
Considerations
This section contains some important considerations when using Network
Login on your Switch.
Before you enable Network Login you must ensure that:
RADIUS has been configured on the Switch.
The RADIUS server in your network is operational.
If the RADIUS server fails or is unavailable, client devices will be unable
to access the network.
Network Access Server
(Switch 3848)
Network Access Client
(Client Device)
Authentication
Information
Authentication
Information
RADIUS Server