Version 6 SuperStack 3 Switch 4400 Management Interface Reference Guide

Table Of Contents
Web Management Interface - Security Network Access Port Security
http://support.3com.com/infodeli/tools/switches/4400/DHA1720-3AAA08/htmweb/accessportsecurity.htm[11/15/2010 3:44:32 PM]
the MAC-based authentication is configured to deny access to all secure network
resources. It is intended to prevent access to secure network resources if a
particular edge device is authorized by RADA (e.g. if a PC is known to be infected by
a virus) and placed on a seperate ‘safe’ VLAN.
Rada Or Network Login (Mixed Secure Network Login and Rada-based
Network Access)
This mode provides for both 802.1X and RADA authentication to be operated in
parallel. It provides a migration path where a single port may be shared by a
number of devices at different times, only some of which support 802.1X. It also
allows a single port configuration to be used throughout a switch, regardless of the
type of device that is to be connected. For example this mode could be used in
education, where a large and varied range of “student” PCs and devices can use
Rada authentication, but permanent staff require a secure log-in to enhanced
services.
This mode can only be considered totally secure if the Rada–based authentication is
configured to deny access to secure network resources, and where 802.1X Network
Login does not share a port (i.e. not via a hub).
RADA And Network Login (“White List” Mode)
This mode allows access by authenticating the MAC address of a host. If this
succeeds, then Network Login must also be used to authenticate the user on this
device.
This mode is referred as the “White list” mode, as it permits log-in from not only
known users, but also from only trusted hosts.
Spanning Tree Edge Port mode - If possible, when a port is configured for
Network Login, it should also be configured to be a Spanning Tree Protocol (STP)
edge port. This minimizes the delay before STP places the port into the forwarding
state. Select Auto for a short delay, Enable for no delay or Disable for standard
STP delay.
If Spanning Tree is running, the STP FastStart setting controls how long the port will
delay, after the link comes up, before determining it is not connected to another
Bridge and user traffic is accepted.
(Auto=short delay, Enable=no delay, Disable=standard STP delay).
If you select No Security or Network Login, the final Port Security page is
displayed. Click the Finish button to assign the security configuration to the selected
port(s).
If you select Continuous Learning or Automatic Learning, the next Port Security
page is displayed. Go to Step 3.
3. Enter the number of authorised addresses you wish to have for the port(s).
This value is potentially between 0 and 255. Each port can be configured between zero
and the number of addresses not currently allocated to other ports. By default one secure
address is pre-allocated to each port.
4. If you selected Automatic Learning, Network Login (secure) or Network Login
with NBX in step 2, select whether you wish to enable or disable Disconnect Unauthorized
Devices (DUD).
5. If you selected Automatic Learning, Network Login (secure) or Network Login
with NBX in step 2, select whether you wish VLAN and QoS parameters for the user
assigned to the port to be supplied by RADIUS or the switch.
6. If you selected Rada, Rada Or Network Login or Rada Else Network Login in step 2,
enter the number of authorized address for the port. Select whether you wish to allow