802.1X Port Configuration

Tab. 802.1X Setting Options per Port, entries in the configuration table

Parameters

Meaning

Possible values

Default setting

Port Initialization

Reset the initialization function. Setting this attribute to “true” causes the device to reset the function for this port. When the resetting process is concluded, the value is reset to “false”.

true, false

false

Port Reauthentication

Activating and deactivating the reauthentication of the port. Setting this attribute “true” causes the device to ask the supplicant to reauthenticate itself on this port. The device resets the value to “false” following a reauthentication.

true, false

false

Authentication Activity

Displays the current status of the authentication activity.

1 = initialized

2 = disconnected

3 = connecting

4 = authenticating
5 = authenticated

6 = aborting authenticating

7 = temporarily not authenticated (held)

8 = access without authentication (force authorized)

9 = no access (force unauthorized)

Backend Authentication State

Displays the current status of the authentication server.

1 = request

2 = response

3 = success

4 = fail

5 = timeout

6 = idle

7 = initialize

Authentication State

Displays the current value of the authentication status for the port.

authorized = the connected subscriber is authenticated

unauthorized = the connected subscriber is not authenticated

Maximum Users

Maximum number of clients that the device authenticates on a port at the same time.
This parameter is effective if you have set the port control (see below) to macBased.

1 - 16

16

Port Control

Setting for the port access control.

Note:
  • In the ForceAuthorized, ForceUnauthorized and auto modes the Switch opens or blocks the port for all clients.Use these modes if you are connecting a single client to the Switch.
  • In the macBased mode the Switch authenticates the clients based on the individual MAC addresses and allows or blocks their data traffic separately. Use this mode if you want to use multi-client authentication or the “MAC Authentication Bypass” function.

  • ForceAuthorized: Access is also available for all clients without authentication.

  • ForceUnauthorized: Access is blocked for all clients, even for clients with authentication.

  • auto: Access to the port depends on the result of the authentication.

  • macBased: Behavior like for auto. Access is also available for clients with a MAC address which the client uses in the course of authentication.

ForceAuthorized

Quiet Period

Period in seconds in which the authentication process does not expect authentication from the supplicants.

0-65535

60

Transmit Period

Wait period before the device resends an EAP packet.

1-65535

30

Supplicant Timeout Period

Excess time in seconds for the communication between the device and the supplicant.

1-65535

30

Server Timeout

Excess time in seconds for the communication between the device and the server.

1-65535

30

Max. Request Constant

Maximum number of request attempts to the supplicants before the authentication process terminates.

1-10

2

Assigned VLAN ID

VLAN that the Switch assigned to the port. The port is an untagged member in this VLAN and the port VLAN ID has the same value.

Prerequisite: The port control is set to auto.

Note: If you are using the multi-client setting by setting “Port Control” to macBased, take into account:

0 - 4094

0

Assignment Reason

Reason for assigning the VLANs to the port.

Prerequisite: The port control is set to auto.

Note: If you are using the multi-client setting by setting “Port Control” to macBased, take into account:

notAssigned

radius

unauthenticatedVLAN

notAssigned

Reauthentication Period

Time in seconds after which the device requests another authentication from the supplicant.

1-65535

3600

Reauthentication Enabled

Enabling or disabling reauthentication

Selected (on),
Not selected (off)

Not selected (off)

Guest VLAN ID

ID of a VLAN that the Switch assigns to the port, if:

  • the 802.1X protocol is active on the port and the port control is set to auto or macBased,

  • a client wants to receive data traffic

  • and EAPOL frames from the client fail to appear, i.e. the client does not support the 802.1X protocol.

The Switch:

  • switches the port to the authenticated state,

  • allows data traffic,

  • but only to the guest VLAN.

Specify a guest VLAN ID if you want to allow devices without 802.1X support access to a guest VLAN.

Note:
  • Use only as a guest VLAN a VLAN that you have set up statically in the Switch.
  • However, if a client connects via 802.1X and his authentication fails, then the Switch only gives him access to the unauthenticated VLAN.
  • When you activate the MAC Authorized Bypass (MAB) function, the device automatically sets the guest VLAN ID to 0.

0 - 4094

With a VLAN ID of 0, the Switch blocks the data traffic because it denies a VLAN setup with this ID.

0

Guest VLAN Period

Time that the Switch waits for EAPOL frames after connecting a device on this port in order to determine whether it supports the 802.1X protocol.

If this time elapses, the Switch only provides access to the guest VLAN for the device connected.

1 - 300 s

90 s

Unauthenticated VLAN ID

ID of a VLAN that the Switch assigns to the port, if:

  • the 802.1X protocol is active on the port,

  • the Switch receives EAPOL frames from the client, i.e. the client supports the 802.1X protocol,

  • and the client's authentication fails.

The Switch:

  • switches the port to the authenticated state,

  • allows data traffic,

  • but only to the unauthenticated VLAN.

Specify a VLAN ID for unauthenticated devices, if:

  • you want to allow devices access to a particular VLAN,

  • these devices do indeed support 802.1X,

  • but their identity and authenticity are unknown to your network.

Note:
  • Use only as an unauthenticated VLAN a VLAN that you have set up statically in the Switch.

0 - 4094

With a VLAN ID of 0, the Switch blocks the data traffic because it denies a VLAN setup with this ID.

0

MAC Authorized Bypass Enable

The Switch makes authenticated access available via MAB, if:

  • You have set the “Port Control” to macBased,

  • a device wants to receive data traffic employing a particular known MAC address,

  • this device does not authenticate itself via 802.1X and

  • the RADIUS server recognizes the MAC addresses authorized to access.

The Switch:

  • waits for the guest VLAN interval to elapse in order to do this,

  • then sends a query to the RADIUS server and in doing so uses the MAC address as the user name and the password.

Activate this function, if:

  • you want to allow particular devices normal access,

  • however these devices do not support 802.1X.

Note:
  • If the RADIUS server denies the MAB authentication, the Switch blocks the access for the device.
  • When you activate the function, the device automatically deactivates guest VLAN access.

On

Off

Off


Buttons

Tab. Buttons (Forts.)

Button

Meaning

“Set”

Transfers the changes to the volatile memory (RAM) of the device. To permanently save the changes afterwards, you open the Basic Settings:Load/Save dialog and click “Save”.

“Reload”

Updates the fields with the values that are saved in the volatile memory (RAM) of the device.

“Help”

Opens the online help.