For 802.1X clients, wired authentication works only if the clients are directly attached to the wired authentication port, or are attached through a hub that does not block forwarding of packets from the client to the PAE group address (01:80:c2:00:00:03). Wired authentication works in accordance with the 802.1X specification, which prohibits a client from sending traffic directly to an authenticator’s MAC address until the client is authenticated. Instead of sending traffic to the authenticator’s MAC address, the client sends packets to the PAE group address. The 802.1X specification prohibits networking devices from forwarding PAE group address packets, because this would make it possible for multiple authenticators to acquire the same client.

For non-802.1X clients, who use MAC authentication, WebAAA, or last-resort authentication, wired authentication works if the clients are directly attached or indirectly attached.

Examples: The following command sets port 5 for a wired authentication user:

DWS-1008# set port type wired-auth 5 success: change accepted.

Examples: The following command sets port 6 for a wired authentication user and specifies a maximum of three simultaneous user sessions:

DWS-1008# set port type wired-auth 6 max-sessions 3 success: change accepted.

See Also:

clear port type

set port type

D-Link DWS-1008 CLI Manual

54

Page 57
Image 57
D-Link dws-1008 manual Clear port type Set port type Link DWS-1008 CLI Manual