•
single
—Authenticates only the first end device. All other end devices that connect later
to the port are allowed full access without any further authentication. They effectively
“piggyback” on the end devices’ authentication.
•
single-secure
—Allows only one end device to connect to the port. No other end device
is allowed to connect until the first logs out.
•
multiple
—Allows multiple end devices to connect to the port. Each end device will be
authenticated individually.
Network access can be further defined using VLANs and firewall filters, which both act
as filters to separate and match groups of end devices to the areas of the LAN they
require.
802.1X Features Overview
802.1X features on Juniper Networks EX Series Ethernet Switches are:
•
Guest VLAN—Provides limited access to a LAN, typically just to the Internet, for end
devices that fail 802.1X authentication.
•
Server-reject VLAN—Provides limited access to a LAN, typically just to the Internet, for
end devices that fail MAC RADIUS authentication.
•
Dynamic VLAN—Enables an end device, after authentication, to be a member of a
VLAN dynamically.
•
Private VLAN—Enables configuration of 802.1X authentication on interfaces that are
members of private VLANs (PVLANs).
•
Dynamic changes to a user session—Allows the switch administrator to terminate an
already authenticated session. This feature is based on support of the RADIUS
Disconnect Message defined in RFC 3576.
•
Support for VoIP—Supports IP telephones. If the phone is 802.1X-enabled, it is
authenticated like any other supplicant. If the phone is not 802.1X-enabled, but has
another 802.1X-compatible device connected to its data port, that device is
authenticated, and then VoIP traffic can flow to and from the phone (providing that
the interface is configured in single mode and not in single-secure mode).
NOTE:
Configuring a VoIP VLAN on private VLAN (PVLAN) interfaces is
not supported.
•
RADIUS accounting—Sends accounting information to the RADIUS accounting server.
Accounting information is sent to the server whenever a subscriber logs in or logs out
and whenever a subscriber activates or deactivates a subscription.
•
Vendor Specific Attributes (VSAs)—Supports the
Juniper-Switching-Filter
attribute
on the RADIUS authentication server that can be used further define a supplicant's
access during the 802.1X authentication process. Centrally configuring VSAs on the
authentication server does away with the need to configure these same attributes in
Copyright © 2010, Juniper Networks, Inc.
2532
Complete Software Guide for Junos
®
OS for EX Series Ethernet Switches, Release 10.3
Summary of Contents for JUNOS OS 10.3 - SOFTWARE
Page 325: ...CHAPTER 17 Operational Mode Commands for System Setup 229 Copyright 2010 Juniper Networks Inc ...
Page 1323: ...CHAPTER 56 Operational Mode Commands for Interfaces 1227 Copyright 2010 Juniper Networks Inc ...
Page 2841: ...CHAPTER 86 Operational Commands for 802 1X 2745 Copyright 2010 Juniper Networks Inc ...
Page 3367: ...CHAPTER 113 Operational Mode Commands for CoS 3271 Copyright 2010 Juniper Networks Inc ...
Page 3435: ...CHAPTER 120 Operational Mode Commands for PoE 3339 Copyright 2010 Juniper Networks Inc ...
Page 3529: ...CHAPTER 126 Operational Mode Commands for MPLS 3433 Copyright 2010 Juniper Networks Inc ...