Netgear GS748Tv5 Software Administration Manual - Page 196

Guest VLAN Period, Unathenticated VLAN ID

Page 196 highlights

GS716Tv3, GS724Tv4, and GS748Tv5 Smart Switches - Unauthorized. The system denies the selected interface system access by moving the interface into unauthorized state. The switch cannot provide authentication services to the client through the interface. - MAC based. This mode allows multiple supplicants connected to the same port to each authenticate individually. Each host connected to the port must authenticate separately in order to gain access to the network. The hosts are distinguished by their MAC addresses. • Guest VLAN ID. Specify the VLAN ID for the guest VLAN. The guest VLAN allows the port to provide a distinguished service to unauthenticated users. This feature provides a mechanism to allow users access to hosts on the guest VLAN. • Guest VLAN Period. Specify the number of seconds that the port remains in the quiet state following a failed authentication exchange. • Unathenticated VLAN ID. Specify the VLAN ID of the unauthenticated VLAN. Hosts that fail the authentication might be denied access to the network or placed on a VLAN created for unauthenticated clients. This VLAN might be configured with limited network access. • Periodic Reauthentication. Select Enable to allow periodic reauthentication of the supplicant for the specified port. • Reauthentication Period. Specify the amount of time that clients can be connected to the port without being reauthenticated. If this field is disabled, connected clients are not forced to reauthenticate periodically. • Quiet Period. Specify the number of seconds that the port remains in the quiet state following a failed authentication exchange.While in the quite state, the port does not attempt to acquire a supplicant. • Resending EAP. Specify the transmit period for the selected port. The transmit period is the value, in seconds, of the timer used by the authenticator state machine on the specified port to determine when to send an EAPOL EAP Request/Identify frame to the supplicant. • Max EAP Requests. Specify the maximum requests for the selected port. The maximum requests value is the maximum number of times the authenticator state machine on this port will retransmit an EAPOL EAP Request/Identity before timing out the supplicant. • Supplicant Timeout. Specify the supplicant time-out for the selected port. The supplicant time-out is the value, in seconds, of the timer used by the authenticator state machine on this port to time-out the supplicant. • Server Timeout. Specify the amount of time that lapses before the switch resends a request to the authentication server. 4. Click the Apply button. Managing Device Security 196

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290

Managing Device Security
196
GS716Tv3, GS724Tv4, and GS748Tv5 Smart Switches
-
Unauthorized
. The system denies the selected interface system access by
moving the interface into unauthorized state. The switch cannot provide
authentication services to the client through the interface.
-
MAC based
. This mode allows multiple supplicants connected to the same port to
each authenticate individually. Each host connected to the port must authenticate
separately in order to gain access to the network. The hosts are distinguished by
their MAC addresses.
Guest VLAN ID
. Specify the VLAN ID for the guest VLAN. The guest VLAN allows the
port to provide a distinguished service to unauthenticated users. This feature provides
a mechanism to allow users access to hosts on the guest VLAN.
Guest VLAN Period
. Specify the number of seconds that the port remains in the
quiet state following a failed authentication exchange.
Unathenticated VLAN ID
. Specify the VLAN ID of the unauthenticated VLAN. Hosts
that fail the authentication might be denied access to the network or placed on a
VLAN created for unauthenticated clients. This VLAN might be configured with limited
network access.
Periodic Reauthentication
. Select
Enable
to allow periodic reauthentication of the
supplicant for the specified port.
Reauthentication Period
. Specify the amount of time that clients can be connected
to the port without being reauthenticated. If this field is disabled, connected clients are
not forced to reauthenticate periodically.
Quiet Period
. Specify the number of seconds that the port remains in the quiet state
following a failed authentication exchange.While in the quite state, the port does not
attempt to acquire a supplicant.
Resending EAP
. Specify the transmit period for the selected port. The transmit period
is the value, in seconds, of the timer used by the authenticator state machine on the
specified port to determine when to send an EAPOL EAP Request/Identify frame to
the supplicant.
Max EAP Requests
. Specify the maximum requests for the selected port. The
maximum requests value is the maximum number of times the authenticator state
machine on this port will retransmit an EAPOL EAP Request/Identity before timing out
the supplicant.
Supplicant Timeout
. Specify the supplicant time-out for the selected port. The
supplicant time-out is the value, in seconds, of the timer used by the authenticator
state machine on this port to time-out the supplicant.
Server Timeout
. Specify the amount of time that lapses before the switch resends a
request to the authentication server.
4.
Click the
Apply
button.