Netgear GS516TP Software Administration Manual - Page 128

Port Authentication, Authentication List

Page 128 highlights

GS516TP Gigabit Smart Switches Note: If 802.1x is enabled, authentication is performed by a RADIUS server. This means the primary authentication method must be RADIUS. To set the method, go to Security  Management Security  Authentication List and select RADIUS as method 1 for defaultList. For more information, see Authentication List Configuration . 3. Select the radio button in the guest VLAN field to enable or disable Guest VLAN and have untagged incoming frames go to the Guest VLAN. 4. If you enable the guest VLAN, select the guest VLAN ID. 5. Enter the Guest VLAN Period. 6. Next to the EAPOL Flood Mode field, select whether to enable or disable radio button forwarding of EAPoL frames when 802.1x is disabled on the device. 7. Click APPLY to update the switch with the new settings. Port Authentication Use the Port Authentication screen to enable and configure port access control on one or more ports.  To configure 802.1x settings for the port: 1. Select Security > Port Authentication > Advanced > Port Authentication. Note: Use the horizontal scroll bar at the bottom of the browser to view all the fields on the Port Authentication screen. The following figures are both images of the Port Authentication screen. 2. Select the check box next to the port to configure. You can also select multiple check boxes to apply the same settings to the select ports, or select the check box in the heading row to apply the same settings to all ports. 3. For the selected ports, specify the following settings: • Port Control. Defines the port authorization state. The control mode is set only if the link status of the port is link up. The possible field values are: • Auto. Automatically detect the mode of the interface. • Authorized. Place the interface into an authorized state without being authenticated. The interface sends and receives normal traffic without client port-based authentication. • Unauthorized. Deny the selected interface system access by moving the interface into unauthorized state. The switch cannot provide authentication services to the client through the interface. 128

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208

128
GS516TP Gigabit Smart Switches
Note:
If 802.1x is enabled, authentication is performed by a RADIUS
server. This means the primary authentication method must be
RADIUS. To set the method, go to
Security
Management
Security
Authentication List
and select
RADIUS
as method 1 for
defaultList. For more information, see
Authentication List
Configuration
.
3.
Select the radio button in the guest VLAN field to enable or disable Guest VLAN and have
untagged incoming frames go to the Guest VLAN.
4.
If you enable the guest VLAN, select the guest VLAN ID.
5.
Enter the Guest VLAN Period.
6.
Next to the EAPOL Flood Mode field, select whether to enable or disable radio button
forwarding of EAPoL frames when 802.1x is disabled on the device.
7.
Click
APPLY
to update the switch with the new settings.
Port Authentication
Use the Port Authentication screen to enable and configure port access control on one or
more ports.
To configure 802.1x settings for the port:
1.
Select
Security > Port Authentication > Advanced > Port Authentication
.
Note:
Use the horizontal scroll bar at the bottom of the browser to view all
the fields on the Port Authentication screen. The following figures
are both images of the Port Authentication screen.
2.
Select the check box next to the port to configure. You can also select multiple check boxes
to apply the same settings to the select ports, or select the check box in the heading row to
apply the same settings to all ports.
3.
For the selected ports, specify the following settings:
Port Control
. Defines the port authorization state. The control mode is set only if the
link status of the port is link up. The possible field values are:
Auto
. Automatically detect the mode of the interface.
Authorized
. Place the interface into an authorized state without being
authenticated. The interface sends and receives normal traffic without client
port-based authentication.
Unauthorized
. Deny the selected interface system access by moving the
interface into unauthorized state. The switch cannot provide authentication
services to the client through the interface.