D-Link DGS-3200-10 Product Manual - Page 192

IGMP Access Control Settings (IGMP Authentication

Page 192 highlights

xStack® DGS-3200 Series Layer 2 Gigabit Ethernet Managed Switch IGMP Access Control Settings (IGMP Authentication) Users can set IGMP a uthentication, otherwise known a s IGMP acces s control, on i ndividual port s on the Switch. When t he Authentication State is Enabled, a nd t he Switch receives an IGMP join re quest, t he Switch will se nd t he acce ss request to th e RADIUS server to do the authentication. IGMP authentication processes IGMP reports as follows: When a host sends a join message for the interested multicast group, the Switch has to do authentication before learning the multicast group/port. The Switch sends an Access-Request to an authentication server and the information including host MAC, switch port number, switch IP, and multicast group IP. When the Access-Accept is answered from the authentication server, the Switch learns the multicast group/port. When the Access-Reject is answered from the authentication server, the Switch won't learn the multicast group/port and won't process the packet further. The entry (host MAC, switch port nu mber, an d multicast g roup IP) is pu t in th e "authentication failed list." Wh en there is n o an swer fro m th e authentication server after T1 time, the Switch resends the Access-Request to the server. If the Switch doesn't receive a response after N1 times, the result is denied and the entry (host MAC, switch port number, multicast group IP) is put in the "authentication failed list." In general case, when the multicast group/port is already learned by the switch, it won't do the authentication again. It only processes the packet as standard. IGMP authentication processes IGMP leaves as follows: When the host sends leave message for the specific multicast group, the Switch fo llows th e stand ard procedure for leaving a gr oup and t hen send s an A ccounting-Request t o th e accoun ting serv er fo r notification. If there is no a nswer from the accounting server a fter T 2 t ime, the Switc h resends the Accounting-Request to t he server. The maximum number of retry times is N2. To view the following window, click Security > IGMP Access Control Settings: Figure 5 - 63. IGMP Access Control Settings window To set up IGMP access control on individual ports for the Switch, complete the following fields: Parameter Description From Port To Port Use this drop-down menu to select the beginning port of a range of ports to be enabled/disabled as IGMP access control ports. Use this drop-down menu to select the ending port of a range of ports to be enabled/disabled as IGMP access control ports. Authentication State Toggle to enable and disable the RADIUS authentication function on the specified ports. Click Apply to implement the changes made. 179

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302

xStack
®
DGS-3200 Series Layer 2 Gigabit Ethernet Managed Switch
179
IGMP Access Control Settings (IGMP Authentication)
Users can set
IGMP a uthentication, otherwise known a s IGMP acces s control, on i
ndividual port s on the Switch.
When t he
Authentication State is
Enabled
, a nd t he Switch receives an IGMP join re quest, t he Switch will se nd t he acce ss request to th e
RADIUS server to do the authentication.
IGMP authentication processes IGMP reports as follows: When a host sends a join message for the interested multicast group, the
Switch has to do authentication before learning the multicast group/port. The Switch sends an Access-Request to an authentication
server and the information including host MAC, switch port number, switch IP, and multicast group IP. When the Access-Accept
is answered from the authentication server, the Switch learns the multicast group/port. When the Access-Reject is answered from
the authentication server, the Switch won’t learn the multicast group/port and won’t process the packet further. The entry (host
MAC, switch port nu mber, an d m ulticast g roup IP) is pu t in th e “authentication failed list.” Wh en t here is n o an swer fro m th e
authentication server after T1 time, the Switch resends the Access-Request to the server. If the Switch doesn’t receive a response
after N1 times, the result is denied and the entry (host MAC, switch port number, multicast group IP) is put in the “authentication
failed list.” In general case, when the multicast group/port is already learned by the switch, it won’t do the authentication again. It
only processes the packet as standard.
IGMP authentication processes IGMP leaves as follows: When the host sends leave message for the specific multicast group, the
Switch fo llows th e stand ard procedure for leaving a gr oup and t hen send s an A ccounting-Request t o th e accoun ting serv er fo r
notification. If there is no a nswer from the accounting server a fter T 2 t ime, the Switc h resends the Accounting-Request to t he
server. The maximum number of retry times is N2.
To view the following window, click
Security
>
IGMP Access Control Settings
:
Figure 5 - 63. IGMP Access Control Settings window
To set up IGMP access control on individual ports for the Switch, complete the following fields:
Parameter
Description
From Port
Use this drop-down menu to select the beginning port of a range of ports to be
enabled/disabled as IGMP access control ports.
To Port
Use this drop-down menu to select the ending port of a range of ports to be enabled/disabled
as IGMP access control ports.
Authentication State
Toggle to enable and disable
the RADIUS authentication function on the specified ports.
Click
Apply
to implement the changes made.