beautypg.com

Mac-based network access control – D-Link DES-3018 User Manual

Page 158

background image

DES-3010F/DES-3010FL/DES-3010G/DES-3016/DES-3018/DES-3026 Fast Ethernet Switch Manual

145

MAC-Based Network Access Control

802.1X

Client

Network access controlled port

Network access uncontrolled port

RADIUS

Server

Ethernet Switch

802.1X

Client

802.1X

Client

802.1X

Client

802.1X

Client

802.1X

Client

802.1X

Client

802.1X

Client

802.1X

Client

802.1X

Client

802.1X

Client

802.1X

Client

Figure 10- 11. Example of Typical MAC-Based Configuration

In order to successfully make use of 802.1X in a shared media LAN segment, it would be necessary to
create “logical” Ports, one for each attached device that required access to the LAN. The Switch would
regard the single physical Port connecting it to the shared media segment as consisting of a number of
distinct logical Ports, each logical Port being independently controlled from the point of view of EAPOL
exchanges and authorization state. The Switch learns each attached devices’ individual MAC addresses, and
effectively creates a logical Port that the attached device can then use to communicate with the LAN via the
Switch.