D-Link DES-3018 MAC-Based Network Access Control, Example of Typical MAC-Based Configuration

Models: DES-3018

1 260
Download 260 pages 53.54 Kb
Page 158
Image 158

DES-3010F/DES-3010FL/DES-3010G/DES-3016/DES-3018/DES-3026 Fast Ethernet Switch Manual

MAC-Based Network Access Control

Ethernet Switch

RADIUS

Server

 

 

 

 

 

 

 

 

 

 

 

802.1X

802.1X

802.1X

802.1X

802.1X

802.1X

802.1X

802.1X

802.1X

802.1X

802.1X

802.1X

Client

Client

Client

Client

Client

Client

Client

Client

Client

Client

Client

Client

Network access controlled port

Network access uncontrolled port

Figure 10- 11. Example of Typical MAC-Based Configuration

In order to successfully make use of 802.1X in a shared media LAN segment, it would be necessary to create “logical” Ports, one for each attached device that required access to the LAN. The Switch would regard the single physical Port connecting it to the shared media segment as consisting of a number of distinct logical Ports, each logical Port being independently controlled from the point of view of EAPOL exchanges and authorization state. The Switch learns each attached devices’ individual MAC addresses, and effectively creates a logical Port that the attached device can then use to communicate with the LAN via the Switch.

145

Page 158
Image 158
D-Link DES-3018 manual MAC-Based Network Access Control, Example of Typical MAC-Based Configuration