Enterasys 802.1Q Specifikace Strana 6

  • Stažení
  • Přidat do mých příruček
  • Tisk
  • Strana
    / 36
  • Tabulka s obsahem
  • KNIHY
  • Hodnocené. / 5. Na základě hodnocení zákazníků
Zobrazit stránku 5
Authentication Overview
April 15, 2011 Page 6 of 36
Figure 1 Applying Policy to Multiple Users on a Single Port
MultiAuth Authentication
Authenticationmodesupportprovidesforthe globalsettingofasingleauthenticationmode
802.1X(strictmode)ormultiplemodes(MultiAuth)peruserorportwhenauthenticating.
Strictmodeistheappropriatemodewhenauthenticatingasingle802.1Xuser.Alltrafficonthe
portreceivesthesamepolicyinstrictmode.When
authenticatingPWA,CEP,orMAC,youmust
useMultiAuthauthentication,whetherauthenticatingasingleormultiplesupplicants.
MultiAuthauthenticationsupportsthesimultaneousconfigurationofuptothreeauthentication
methodsperuseronthesameport,butonlyonemethodperuserisactuallyapplied.When
MultiAuthauthenticationportshaveacombination
ofauthenticationmethodsenabled,andauser
issuccessfullyauthenticatedformorethanonemethodatthesametime,theconfigured
authenticationmethodprecedencewilldeterminewhichRADIUSreturnedFilterIDwillbe
processedandresultinanappliedtrafficpolicyprofile.SeeSettingMultiAuthAuthentication
Precedenceonpage 21
forauthenticationmethodprecedencedetails.
ThenumberofusersordevicesMultiAuthauthenticationsupportsdependsuponthetypeof
device,whethertheportsarefixedaccessoruplink,andwhetherincreasedportcapacityorextra
chassisusercapacityMUAlicenseshavebeenapplied.Seethefirmwarecustomerreleasenote
thatcomes
withyourdevicefordetailsonthenumberofusersordevicessupportedperport.
InFigure 2,multipleusersareauthenticatedonasingleporteachwithadifferentauthentication
method.Inthiscase,eachuseronasingleportsuccessfullyauthenticateswithadifferent
authenticationtype.Theauthenticationmethodis
includedintheauthenticationcredentialssent
totheRADIUSserver.RADIUSlooksuptheuseraccountforthatuserbasedupontheSMAC.The
FilterIDforthatuserisreturnedtotheswitchintheauthenticationresponse,andthe
authenticationisvalidatedforthatuser.
User 1
SMAC
00-00-00-11-11-11
User 2
SMAC
00-00-00-22-22-22
User 3
SMAC
00-00-00-33-33-33
Authentication
Request
Authentication
Credentials User 2
User1 Filter ID --> Policy X
User2 Filter ID --> Policy Y
User3 Filter ID --> Policy Z
Authentication
Credentials User 1
Authentication
Credentials User 3
Dynamic Admin Rule
for Policy 1
SMAC = 00-00-00-11-11-11
ge.1.5
Dynamic Admin Rule
for Policy 2
SMAC = 00-00-00-22-22-22
ge.1.5
Dynamic Admin Rule
for Policy 3
SMAC = 00-00-00-33-33-33
ge.1.5
Authentication
Response
Authentication
Request
Authentication
Response
Authentication
Request
Switch
Authentication
Response
Radius Server
Port ge.1.5
Zobrazit stránku 5
1 2 3 4 5 6 7 8 9 10 11 ... 35 36

Komentáře k této Příručce

Žádné komentáře