Netgear FS728TLP Web Management User Guide - Page 162

Backend State, Authenticator PAE

Page 162 highlights

ProSAFE FS526Tv2, FS726Tv2, and FS728TLP Smart Switches Setting Authenticator PAE State Backend State Description This is a nonconfigurable field that shows the state of the authenticator port access entity (PAE): • Initialize. If the following circumstances occur, the port can enter the Initialize state from any other state: - The port is being initialized. - The Port Control field is set to Auto but the port is not in Auto mode. - The MAC address of the port is invalid. • Disconnected. If the smart switch receives an explicit logoff request from the supplicant, the port can enter the Disconnected state from the Connecting, Authenticated, or Aborting state. If the number of permissible reauthentication attempts is exceeded, the port can also enter the Disconnected state from the Connecting state. • Connecting. The port is operable and the PAE attempts to establish communication with a supplicant. • Authenticating. The supplicant is being authenticated. • Authenticated. The authenticator authenticated the supplicant successfully and the Port Status field (see View the Port Summary on page 164) displays Authorized. • Aborting. The authentication procedure is being aborted prematurely because the smart switch received a reauthentication request, an EAPoL-Start frame, or an EAPoL-Logoff frame, or the authorization timed out. • Held. The smart switch discarded all EAPoL packets for the port to prevent an attack. • ForceAuthorized. The smart switch sent an EAP Success packet to the supplicant, and the Port Status field (see View the Port Summary on page 164) displays Authorized. • ForceUnauthorized. The smart switch sent an EAP Failure packet to the supplicant, and the Port Status field (see View the Port Summary on page 164) displays Unauthorized. This is a nonconfigurable field that shows the state of the back-end authentication for the port: • Request. The smart switch received an EAP Request packet from the authentication server and relayed the packet as an EAPoL-encapsulated frame to the supplicant. • Response. The smart switch received an EAPoL-encapsulated EAP Response packet (either a Response/Identity or a Response packet) from the supplicant and relayed the EAP packet to the authentication server. • Success. The authentication session completed successfully. • Fail. The authentication session failed. • Timeout. The authentication session timed out. If the port is in the Unauthorized state, the smart switch sends an EAP Failure message to the supplicant. • Initialize. The port is being initialized. • Idle. The smart switch waits for a new authentication session. Manage RADIUS and Port Authentication and Traffic Control 162

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335

Manage RADIUS and Port
Authentication and Traffic Control
162
ProSAFE FS526Tv2, FS726Tv2, and FS728TLP Smart Switches
Authenticator PAE
State
This is a nonconfigurable field that shows the state of the authenticator port
access entity (PAE):
Initialize
. If the following circumstances occur, the port can enter the Initialize
state from any other state:
-
The port is being initialized.
-
The Port Control field is set to Auto but the port is not in Auto mode.
-
The MAC address of the port is invalid.
Disconnected
. If the smart switch receives an explicit logoff request from the
supplicant, the port can enter the Disconnected state from the Connecting,
Authenticated, or Aborting state. If the number of permissible reauthentication
attempts is exceeded, the port can also enter the Disconnected state from the
Connecting state.
Connecting
. The port is operable and the PAE attempts to establish
communication with a supplicant.
Authenticating
. The supplicant is being authenticated.
Authenticated
. The authenticator authenticated the supplicant successfully
and the Port Status field (see
View the Port Summary
on page
164) displays
Authorized.
Aborting
. The authentication procedure is being aborted prematurely
because the smart switch received a reauthentication request, an
EAPoL-Start frame, or an EAPoL-Logoff frame, or the authorization timed out.
Held
. The smart switch discarded all EAPoL packets for the port to prevent an
attack.
ForceAuthorized
. The smart switch sent an EAP Success packet to the
supplicant, and the Port Status field (see
View the Port Summary
on
page
164) displays Authorized.
ForceUnauthorized
. The smart switch sent an EAP Failure packet to the
supplicant, and the Port Status field (see
View the Port Summary
on
page
164) displays Unauthorized.
Backend State
This is a nonconfigurable field that shows the state of the back-end authentication
for the port:
Request
. The smart switch received an EAP Request packet from the
authentication server and relayed the packet as an EAPoL-encapsulated
frame to the supplicant.
Response
. The smart switch received an EAPoL-encapsulated EAP
Response packet (either a Response/Identity or a Response packet) from the
supplicant and relayed the EAP packet to the authentication server.
Success
. The authentication session completed successfully.
Fail
. The authentication session failed.
Timeout
. The authentication session timed out. If the port is in the
Unauthorized state, the smart switch sends an EAP Failure message to the
supplicant.
Initialize
. The port is being initialized.
Idle
. The smart switch waits for a new authentication session.
Setting
Description