beautypg.com

3 802.1x – PLANET WGSW-48000 User Manual

Page 92

background image

User’s Manual of WGSW-48000

92

„

ACL Port select

Figure 4-7-5 ACL Port List

1.

If the rule/filter of ACL entry is empty, the check box of this entry will not be checked by default.

2.

If the check box is not checked, the corresponding ACL entry will not be programmed to hardware.

3.

Before input MAC, IP, port number, Packet type or Ether type, you have to check the corresponding

check box of rule/filter.

4.

The count of ACL entries which own PORT rule/filter have to be smaller than 8, otherwise it would

cause NO RESOURCE when add ACL entry.

4.7.3 802.1x

„

Overview of 802.1X Port-Based Authentication

In the 802.1X-world, the user is called the supplicant, the switch is the authenticator, and the RADIUS server is the

authentication server. The switch acts as the man-in-the-middle, forwarding requests and responses between the supplicant

and the authentication server. Frames sent between the supplicant and the switch are special 802.1X frames, known as EAPOL

(EAP Over LANs) frames. EAPOL frames encapsulate EAP PDUs (RFC3748). Frames sent between the switch and the

RADIUS server are RADIUS packets. RADIUS packets also encapsulate EAP PDUs together with other attributes like the

switch's IP address, name, and the supplicant's port number on the switch. EAP is very flexible, in that it allows for different

authentication methods, like MD5-Challenge, PEAP, and TLS. The important thing is that the authenticator (the switch) doesn't

need to know which authentication method the supplicant and the authentication server are using, or how many information

exchange frames are needed for a particular method. The switch simply encapsulates the EAP part of the frame into the

relevant type (EAPOL or RADIUS) and forwards it.

When authentication is complete, the RADIUS server sends a special packet containing a success or failure indication. Besides

forwarding this decision to the supplicant, the switch uses it to open up or block traffic on the switch port connected to the