3Com NJ240FX manual Using the Central Configuration Manager

Page 46

42CHAPTER 4: USING THE CENTRAL CONFIGURATION MANAGER

When the option is set to Disable 802.1X, all packets are processed as a normal

Ethernet switch; no 802.1X control applies.

With Standard 802.1X selected, control is enabled. Once the device is authorized, the port it connects to is in the authorized state and all packets entering the port are allowed to pass through.

When the Secure 802.1X option is selected, control is enabled. In addition, the IntelliJack will check its ATU to determine if packets entering the port should be forwarded. If the device is authorized, the IntelliJack will put the MAC address of the device in the ATU and allow its packets to pass through. The NJ240FX will block all other packets that don’t have the correct MAC address specified in the ATU.

You can select the MAC address filter option if a client device does not support 802.1X and wishes to connect to the network through the IntelliJack (e.g., a network printer). In this case, you can manually add the device’s MAC address associated to the port in the ATU, and packets from the network to this port will be blocked unless their MAC addresses are listed in the ATU.

802.1X with IP Phone is a special case of 802.1X secure mode. In this mode, when a 3Com IP phone is connected to the IntelliJack, the phone’s MAC address will be locked into the ATU automatically. Therefore, packets sent from the phone can pass through by default without further authentication. If 802.1X control is not required, an IP phone can connect to a port with 802.1X disabled and voice traffic will pass through without authentication.

24When 802.1X security is applied, authentication is required and reauthentication is required at specific intervals. The IntelliJack disables reauthentication by default.

When reauthentication is enabled, the default period is 3600 seconds. You could select an interval ranging from 10 to 65535 seconds. If you prefer that a supplicant device authenticates itself on a frequent basis, you would choose a small reauthentication interval. Likewise, you would increase the interval or disable the function if you were not concerned about regular authentication of the devices on your network.

25When 802.1x is enabled in the NJ240FX, you have the ability to automatically assign a port to a specific VID when a user connects and authenticates via that port. This option depends on a RADIUS server being configured with user profiles, including VID assignments. When this feature is enabled, the RADIUS server effectively sends the user information to the NJ240FX, which is acting as its client.

NOTE: When a port has been assigned a VLAN ID automatically by the RADIUS server, you will not be able to make any changes to the port's VLAN ID, its VLAN mode, or any entries in the VLAN table to which this port is associated.

Image 46
Contents User Guide United States Government Legend Contents Troubleshooting the NJ240FX Installing the NJ240FX Intellijack Installing the NJ240FX Intellijack About the NJ240FX Before You Begin IntelliJack MountingCabling is connected to an active fiber port Installing the NJ240FX Intellijack Mounting the IntelliJack Installing the NJ240FX Intellijack LED Installing the NJ240FX Intellijack Installing Configuration Managers Configuration Managers Using Local Configuration Manager InitializingUsing the Local Configuration Manager Setting Advanced OptionsUsing the Local Configuration Manager IntelliJacks on Your DiscoveringNetwork Using the Central Configuration Manager Discovering IntelliJacks on Your Network Using the Central Configuration Manager Discovering IntelliJacks on Your Network Viewing Device PropertiesViewing Device Properties General Tab Port InformationProduct Information Hardware Settings Tab Viewing Device Properties Using the Central Configuration Manager Statistics & Log Tab Snmp Settings Tab Viewing Device Properties Advanced Settings Tab Alert Level Notifying Event System Log Settings Tab Configuration Changing DeviceIdentification Settings General ConfigurationHardware Settings Changing Device Configuration Priority & Vlan Configuration Port Based SettingsOther Priority & Vlan Settings Using the Central Configuration Manager Password Security Configuration802.1X Using the Central Configuration Manager Changing Device Configuration Snmp Configuration Changing Device Configuration Advanced Configuration Event Alert LevelsPort Based Controls Alert Level Notifying EventRestoring to Base Configurations Global Setting Default ValueGlobal Setting Default Value Using the Central Configuration Manager Changing Device Configuration Connected to NJ240FX Finding ComputersDevices Upgrading NJ240FX FirmwareUsing the Central Configuration Manager Upgrading the NJ240FX Firmware Using the Central Configuration Manager Upgrading the NJ240FX Firmware Using the Central Configuration Manager Troubleshooting the NJ240FX Troubleshooting the NJ240FX Obtaining Support Contact Us Asia, Pacific Rim Europe, Middle East, and AfricaLatin America North AmericaProduct Specifications Product Specifications Features Jabber Experienced 16 transmission attempts and was discarded. Product Specifications 3COM Corporation Limited Warranty