User manual

C
HAPTER
14
| Security Measures
Network Access
– 169 –
ES-2000 Series
WEB INTERFACE
To configure aging status for secure addresses stored in the MAC address
table by 802.1X:
1. Click Security, Network Access.
2. Select Configure Global from the Step list.
3. Enable or disable aging for secure addresses.
4. Click Apply.
Figure 95: Configuring Global Settings for Network Access
CONFIGURING
NETWORK ACCESS
FOR PORTS
Use the Security > Network Access (Configure Interface) page to enable
dynamic VLAN assignments.
PARAMETERS
These parameters are displayed:
Dynamic VLAN – Enables dynamic VLAN assignment for a port. When
enabled, any VLAN identifiers returned by the RADIUS server through
the 802.1X authentication process are applied to the port, providing the
VLANs have already been created on the switch. (GVRP is not used to
create the VLANs.) (Default: Enabled)
The VLAN settings specified by the first authenticated MAC address
(using the 802.1X authentication process) are implemented for a port.
Other authenticated MAC addresses on the port must have the same
VLAN configuration, otherwise they are treated as authentication
failures.
If dynamic VLAN assignment is enabled on a port and the RADIUS
server returns no VLAN configuration (to the 802.1X authentication
process), the authentication is still treated as a success, and the host is
assigned to the default untagged VLAN.
When the dynamic VLAN assignment status is changed on a port, all
authenticated addresses mapped to that port are cleared from the
secure MAC address table.