Dell PowerConnect W-IAP92 Dell Instant 6.2.0.0-3.2.0.0 User Guide - Page 136

MAC + 802.1X Authentication, Configuring MAC + 802.1X Authentication

Page 136 highlights

4. Select the domain name/URL and click Edit to modify or Delete to remove the entry from the list. 5. Click OK to apply the changes. MAC + 802.1X Authentication This authentication method has the following features: l MAC authentication must succeed before 802.1X authentication The administrator is allowed to enable MAC authentication for 802.1X authentication. MAC authentication shares all the authentication server configurations with 802.1X authentication. If a wireless or wired client connects to the network, MAC authentication is done first. If MAC authentication fails, 802.1X authentication will not begin. If MAC authentication succeeds, 802.1X authentication is carried out. If 802.1X authentication succeeds, the client is assigned an 802.1X authentication role. If 802.1X authentication fails, the client is assigned a deny-all role or mac-auth-only role. l MAC authentication only role Allows an administrator to create a mac-auth-only role (similar to machine-auth-only role concept) for role-based access rules when MAC authentication is enabled for 802.1X authentication. The macauth-only role is assigned to a client if MAC authentication succeeds and 802.1X authentication fails. If 802.1X authentication succeeds, it will be overwritten by the final role. The mac-auth-only role is primarily used for wired clients. l L2 authentication fall-through Allows an administrator to enable the l2-authentication-fallthrough mode. If this option is enabled and MAC authentication fails, 802.1X authentication is still allowed. If this option is disabled, 802.1X authentication is not allowed. The l2-authentication-fallthrough mode is disabled by default. Configuring MAC + 802.1X Authentication To configure the MAC+802.1X authentication for a wireless network: 1. In the Network tab, click the network for which you want to enable MAC+802.1X authentication. The edit link for the network appears. 2. Click the edit link and navigate to the Security tab. 3. For a network with Enterprise level: a. Select the check box Perform MAC authentication before 802.1X if you want to use 802.1X authentication only when MAC authentication is successful. b. Select the check box MAC authentication fail-thru if you want to use 802.1X authentication even when the MAC authentication fails. 136 | Authentication Dell PowerConnect W-Series Instant Access Point 6.2.0.0-3.2.0.0 | User Guide

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296

136
|
Authentication
Dell PowerConnect W-Series Instant Access Point
6.2.0.0-3.2.0.0
|
User Guide
4.
Select the domain name/URL and click
Edit
to modify or
Delete
to remove the entry from the
list.
5.
Click
OK
to apply the changes.
MAC + 802.1X Authentication
This authentication method has the following features:
l
MAC authentication must succeed before 802.1X authentication
The administrator is allowed to enable MAC authentication for 802.1X authentication. MAC
authentication shares all the authentication server configurations with 802.1X authentication.
If a wireless or wired client connects to the network, MAC authentication is done first. If MAC
authentication fails, 802.1X authentication will not begin. If MAC authentication succeeds,
802.1X authentication is carried out. If 802.1X authentication succeeds, the client is assigned
an 802.1X authentication role. If 802.1X authentication fails, the client is assigned a
deny-all
role or
mac-auth-only
role.
l
MAC authentication only role
Allows an administrator to create a
mac-auth-only
role (similar to
machine-auth-only
role
concept) for role-based access rules when MAC authentication is enabled for 802.1X
authentication. The
macauth-only
role is assigned to a client if MAC authentication succeeds
and 802.1X authentication fails. If 802.1X authentication succeeds, it will be overwritten by
the final role. The
mac-auth-only
role is primarily used for wired clients.
l
L2 authentication fall-through
Allows an administrator to enable the
l2-authentication-fallthrough
mode. If this option is
enabled and MAC authentication fails, 802.1X authentication is still allowed. If this option is
disabled, 802.1X authentication is not allowed. The
l2-authentication-fallthrough
mode is
disabled by default.
Configuring MAC + 802.1X Authentication
To configure the MAC+802.1X authentication for a wireless network:
1.
In the
Network
tab, click the network for which you want to enable MAC+802.1X
authentication. The
edit
link for the network appears.
2.
Click the
edit
link and navigate to the
Security
tab.
3.
For a network with
Enterprise
level:
a.
Select the check box
Perform MAC authentication before 802.1X
if you want to use
802.1X authentication only when MAC authentication is successful.
b.
Select the check box
MAC authentication fail-thru
if you want to use 802.1X
authentication even when the MAC authentication fails.