5 Configuration
D-Link Web Smart Switch User Manual
72
Click Apply to implement configuration changes.
AAA > 802.1X > 802.1X Global Settings
Network switches provide easy and open access to resources, by simply attaching a client PC. Unfortunately
this automatic configuration also allows unauthorized personnel to easily intrude and possibly gain access to
sensitive data.
IEEE-802.1X provides a security standard for network access control, especially in Wi-Fi wireless networks.
802.1X holds a network port disconnected until authentication is completed. The switch uses Extensible
Authentication Protocol over LANs (EAPOL) to exchange authentication protocol client identity (such as a
user name) with the client, and forward it to another remote RADIUS authentication server to verify access
rights. The EAP packet from the RADIUS server also contains the authentication method to be used. The
client can reject the authentication method and request another, depending on the configuration of the client
software and the RADIUS server. Depending on the authenticated results, the port is either made available
to the user, or the user is denied access to the network.
Figure 5.97 – AAA > 802.1X > 802.1X Global Settings
NOTE: The Forward EAPOL PDU option will be
useless if the Authentication State is Enabled.
AAA > 802.1X > 802.1X Port Settings
The 802.1X Port Settings page provide users to configure the 802.1X Port settings..
Figure 5.98 – AAA > 802.1X > 802.1X Port Settings
From Port/To Port: Enter the port or ports to be set.
QuietPeriod (0 – 65535): Sets the number of seconds that the switch remains in the quiet state following a
failed authentication exchange with the client. Default is 60 seconds.
ServerTimeout (1 – 65535): Sets the amount of time the switch waits for a response from the client before
resending the response to the authentication server. Default is 30 seconds.
TxPeriod (1 – 65535): This sets the TxPeriod of time for the authenticator PAE state machine. This value
determines the period of an EAP Request/Identity packet transmitted to the client. Default is 30 seconds.
ReAuthentication: Determines whether regular reauthentication will take place on this port. The default
setting is Disabled.
Capability: Indicates the capability of the 802.1X. The possible field values are:
Authenticator – Specify the Authenticator settings to be applied on a per-port basis.
None – Disable 802.1X functions on the port.