Tp-Link T2600G-28MPS V2 [773/1027] Pppoe id insertion

Tp-Link T2600G-28MPS V2 [773/1027] Pppoe id insertion
Configuration Guide 742
Configuring Network Security Network Security
Figure 1-3 802.1X Authentication Model
Authentication Server
Clients
Switch
Authenticator

Client
A client, usually a computer, is connected to the authenticator via a physical port. We
recommend that you install TP-Link 802.1X authentication client software on the client
hosts, enabling them to request 802.1X authentication to access the LAN.

Authenticator
An authenticator is usually a network device that supports 802.1X protocol. As the above
figure shows, the switch is an authenticator.
The authenticator acts as an intermediate proxy between the client and the authentication
server. The authenticator requests user information from the client and sends it to the
authentication server; also, the authenticator obtains responses from the authentication
server and send them to the client. The authenticator allows authenticated clients to
access the LAN through the connected ports but denies the unauthenticated clients.

Authentication Server
The authentication server is usually the host running the RADIUS server program. It stores
information of clients, confirms whether a client is legal and informs the authenticator
whether a client is authenticated.
PPPoE ID-Insertion
In common PPPoE dialup mode, when users dial up through PPPoE, they can access the
network as long as their accounts are authenticated successfully on the RADIUS server. As
a result, the illegal users can embezzle the accounts to access the Internet.
PPPoE ID-Insertion provides a way to resolve this problem. With this feature enabled, the
switch attaches a tag to the PPPoE Active Discovery packets received from the client,
and sends it to the BRAS (Broadband Remote Access Server). The tag records the client
information, such as the connected port number and the MAC address of the client. The

Содержание

Похожие устройства

Скачать