SNR S2989G-24TX-UPS — настройка функций безопасности и аутентификации в сети [343/553]

Превью страниц Страница 343 / 553
SNR S2989G-8TX-POE [343/553] Mab configuration task list
S2989G-24TX Operation Manual
Chapter 6 Security Function Configuration
6-70
When VLAN ACL and Port ACL are configured at the same time, the
principle of denying firstly is used. When the packets match VLAN ACL and
Port ACL at the same time, as long as one rule is drop, then the final action
is drop.
Each ACL of different types can only apply one on a VLAN, such as the
basic IP ACL, each VLAN can applies one only.
6.9
MAB
6.9.1
Introduction to MAB
In actual network existing the device which can not install the authentication client,
such as printer, PDA devices, they can not process 802.1x authentication. However, to
access the network resources, they need to use MAB authentication to replace 802.1x
authentication.
MAB authentication is a network accessing authentication method based on the
accessing port and the MAC address of MAB user. The user needn’t install any
authentication client, after the authentication device receives ARP packets sent by MAB
user, it will authenticate the MAC address of the MAB user and there is the corresponding
authentication information in the authentication server, the matched packets of the port
and the source MAC are allowed to pass when the authentication is successful. MAB user
didn’t need to input the username and password manually in the process of
authentication.
At present, MAB authentication device only supports RADIUS authentication method.
There is the selection method for the authentication username and password: use the
MAC address of the MAB user as the username and password, or the fixed username and
password (all users use the configured username and password to authenticate).
6.9.2
MAB Configuration Task List
MAB Configuration Task List:
1. Enable MAB function
1) Enable global MAB function
2) Enable port MAB function
2. Configure MAB authentication username and password
3. Configure MAB parameters

Содержание

666

Узнайте о конфигурации функций безопасности, таких как VLAN ACL и MAB аутентификация для устройств без клиента. Обеспечьте доступ к сети с помощью эффективных методов.