D-Link DES-1228/ME [174/267] X host based access control

D-Link DES-1228/ME [174/267] X host based access control
DES-1228/ME Layer 2 Fast Ethernet Managed Switch
161
802.1X Host-based Access Control
Figure 10-19. Example of Typical Host-Based Configuration
In order to successfully make use of 802.1X in a shared media LAN segment, it would be necessary to create logicalPorts, one
for each attached device that required access to the LAN. The Switch would regard the single physical Port connecting it to the
shared media segment as consisting of a number of distinct logical Ports, each logical Port being independently controlled from
the point of view of EAPOL exchanges and authorization state. The Switch learns each attached devices individual MAC
addresses, and effectively creates a logical Port that the attached device can then use to communicate with the LAN via the
Switch.
NOTE: To enable Host-based 802.1X, select the MAC-based option in the Switch 802.1X field in
the Device Information window.
RADIUS Attributes Assignment
To assign Ingress/Egress bandwidth by RADIUS server, the proper parameters should be configured on the RADIUS Server. The
tables below show the parameters for bandwidth and default priority:
The parameters of the Vendor-Specific attribute are:
Vendor-Specific attribute Description Value Usage
Vendor-ID Defines the vendor 171 (DLINK) Required
Vendor-Type
The definition of this
attribute
2 (for ingress bandwidth)
3 (for egress bandwidth)
Required

Содержание