SNR S2989G-48TX-RPS — настройка функций безопасности в сетевых устройствах [308/553]

Превью страниц Страница 308 / 553
SNR S2989G-48TX-DC [308/553] The features of vlan allocation
S2989G-24TX Operation Manual
Chapter 6 Security Function Configuration
6-35
network, while the others can not. When one user becomes offline, the other
users will not be affected.
When the user-based (IP address+ MAC address+ port) method is used, all
users can access limited resources before being authenticated. There are two
kinds of control in this method: standard control and advanced control. The
user-based standard control will not restrict the access to limited resources,
which means all users of this port can access limited resources before being
authenticated. The user-based advanced control will restrict the access to limited
resources, only some particular users of the port can access limited resources
before being authenticated. Once those users pass the authentication, they can
access all resources.
Attention: when using private supplicant systems, user-based advanced control is
recommended to effectively prevent ARP cheat.
For the maximum number of the authenticated users, the maximum number of IPv4
users supported by user-based is 700, the maximum number of IPv6 users supported by
user-based is 1400. mac-based relates to ratelimit value of switch, it can supports 4000
authenticated users, but it is recommended that the number of the authenticated users
should not exceed 2000.
6.2.1.7 The Features of VLAN Allocation
1. Auto VLAN
Auto VLAN feature enables RADIUS server to change the VLAN to which the access
port belongs, based on the user information and the user access device information.
When an 802.1x user passes authentication on the server, the RADIUS server will send
the authorization information to the device, if the RADIUS server has enabled the VLAN-
assigning function, then the following attributes should be included in the Access-Accept
messages:
Tunnel-Type = VLAN (13)
Tunnel-Medium-Type = 802 (6)
Tunnel-Private-Group-ID = VLANID
The VLANID here means the VID of VLAN, ranging from 1 to 4094. For example,
Tunnel-Private-Group-ID = 30 means VLAN 30.
When the switch receives the assigned Auto VLAN information, the current Access
port will leave the VLAN set by the user and join Auto VLAN.
Auto VLAN won’t change or affect the port’s configuration. But the priority of Auto
VLAN is higher than that of the user-set VLAN, that is Auto VLAN is the one takes effect
when the authentication is finished, while the user-set VLAN do not work until the user

Содержание

666

Изучите методы настройки функций безопасности для управления доступом пользователей в сетевых устройствах. Узнайте о стандартном и расширенном контроле доступа.