Netgear GS724Tv4 Software Administration Manual - Page 195

Port Authentication, Enable, Apply, To con X settings for the port, Security, Advanced

Page 195 highlights

GS716Tv3, GS724Tv4, and GS748Tv5 Smart Switches 3. In the VLAN Assignment Mode field, select Enable. When enabled, this feature allows a port to be placed into a particular VLAN based on the result of the authentication or type of 802.1X authentication a client uses when it accesses the device. The authentication server can provide information to the device about which VLAN to assign the supplicant. 4. Next to Dynamic VLAN Creation Mode, select Enable. If RADIUS-assigned VLANs are enabled, the RADIUS server is expected to include the VLAN ID in the 802.1X tunnel attributes of its response message to the device. If dynamic VLAN creation is enabled on the device and the RADIUS-assigned VLAN does not exist, then the assigned VLAN is dynamically created. This implies that the client can connect from any port and can get assigned to the appropriate VLAN. This feature gives flexibility for clients to move around the network without much additional configuration required. 5. Next to EAPOL Flood Mode, select Enable. Extensible Authentication Protocol (EAP) over LAN (EAPOL) flood support is enabled on the switch. 6. Click the Apply button. Port Authentication Use the Port Authentication screen to enable and configure port access control on one or more ports.  To configure 802.1X settings for the port: 1. Select Security > Port Authentication > Advanced > Port Authentication. Note: Use the horizontal scroll bar at the bottom of the browser to view all the fields on the Port Authentication screen. 2. Select one or more ports to configure. For information about how to select and configure one or more ports, see Configuring Interface Settings on page 28. 3. Specify the following settings: • Port Control. Defines the port authorization state. The control mode is set only if the link status of the port is link up. Select one of the following options: - Auto. The system automatically detects the mode of the interface. - Authorized. The system places the interface into an authorized state without being authenticated. The interface sends and receives normal traffic without client port-based authentication. Managing Device Security 195

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290

Managing Device Security
195
GS716Tv3, GS724Tv4, and GS748Tv5 Smart Switches
3.
In the VLAN Assignment Mode field, select
Enable
.
When enabled, this feature allows a port to be placed into a particular VLAN based on the
result of the authentication or type of 802.1X authentication a client uses when it
accesses the device. The authentication server can provide information to the device
about which VLAN to assign the supplicant.
4.
Next to Dynamic VLAN Creation Mode, select
Enable
.
If RADIUS-assigned VLANs are enabled, the RADIUS server is expected to include the
VLAN ID in the 802.1X tunnel attributes of its response message to the device. If dynamic
VLAN creation is enabled on the device and the RADIUS-assigned VLAN does not exist,
then the assigned VLAN is dynamically created. This implies that the client can connect
from any port and can get assigned to the appropriate VLAN. This feature gives flexibility
for clients to move around the network without much additional configuration required.
5.
Next to EAPOL Flood Mode, select
Enable
.
Extensible Authentication Protocol (EAP) over LAN (EAPOL) flood support is enabled on
the switch.
6.
Click the
Apply
button.
Port Authentication
Use the Port Authentication screen to enable and configure port access control on one or
more ports.
To configure 802.1X settings for the port:
1.
Select
Security
>
Port Authentication
>
Advanced
>
Port Authentication
.
Note:
Use the horizontal scroll bar at the bottom of the browser to view all
the fields on the Port Authentication screen.
2.
Select one or more ports to configure.
For information about how to select and configure one or more ports, see
Configuring
Interface Settings
on page 28.
3.
Specify the following settings:
Port Control
. Defines the port authorization state. The control mode is set only if the
link status of the port is link up. Select one of the following options:
-
Auto
. The system automatically detects the mode of the interface.
-
Authorized
. The system places the interface into an authorized state without
being authenticated. The interface sends and receives normal traffic without client
port-based authentication.