Configuring 802.1X Authentication
25-2 Authentication Configuration
•LocalusercredentialsusedforlocalauthenticationandauthorizationofCLIandWebView
managementsessions.Fordetails,refertoSettingUserAccountsandPasswordson
page 215andSettingtheAuthenticationLoginMethodonpage 2550.
•RemoteAAAserviceusedforremoteauthentication,authorization,andaccountingofCLI
andWebViewmanagementsessions,aswellasallnetworkaccesssessionsprovisionedby
wayof802.1x,PWA,orMACAuthentication.Fordetails,refertoSettingtheAuthentication
LoginMethodonpage 2550andConfiguring802.1XAuthenticationonpage 252.
• SupportforRADUIS,RFC3580,andTACACS+canbefoundinthefollowingsections:
ConfiguringRADIUSonpage 2553,ConfiguringRFC3580onpage 2560,and
ConfiguringTACACS+onpage 2563

Configuring 802.1X Authentication

About Multi-User Authentication

EnterasysNetworks’enhancedversionoftheIEEE802.1X2001specificationdecreasessecurity
vulnerabilitiesinherentwiththestandardimplementation,andallowsmultipledevicesandusers,
alsoknownas“supplicants,”tobeauthenticatedonasingleport.Theenhancedstandardclearly
distinguisheseachnetworkaccessportfromitsaccess“entities,”whichmaintainauthentication
instructionsassociatedwitheachuniquepotentialsupplicant.
802.1Xenhancementsarebackwardscompatiblewithexisting802.1Xsupplicantsand
configurations,andaredesignedtoseamlesslyintegrateintoEnterasysperuserpolicy
managementsystem;allowingmuchmoregranularcontroloveruserauthorization.
TheEnterasysmultiuser802.1Ximplementationincludesthefollowingcomponents:
•AMultiModeEnabledEnterasysMatrixSystem—onlywhenasystemissettooperatein
multipleauthenticationmode(asdescribedinConfiguringMultipleAuthenticationon
page 271)cantheenhanced802.1Xfeaturebeused.Thesystemʹsportsintendedfornetwork
accesstoauthenticateandauthorizesupplicantswillbeallowedtosimultaneouslyutilize
morethanoneaccessentity.
• AccessEntities—responsibleformaintainingstate,counters,andstatisticsforanindividual
supplicant.Anaccessentityisactivatedfromapoolofconfiguredaccessentitieswhena
potentialsupplicantonaportneedstobeauthenticated.Itbecomesdeactivatedwhenthe
supplicantlogsoff,cannotbeauthenticated,ortheEnterasysMatrixdevicedeterminesthat
thesupplicantorassociatedpolicysettingsarenolongervalid.
• Supplicants—devicesorusersthatdesireaccesstothenetwork,suchasworkstations,
printers,PDAs,orhardwiredorwirelessphones.Thesewillbeidentifiedbythesystemusing
acombinationofconnectionport,MACaddresses,andallocatedaccessentityindex.Oncea
supplicantissuccessfullyauthenticated,thesystemisresponsibleforenforcingthedegreeto
whichthesupplicantwillbeauthorizedtoaccessthenetwork,usinginformationsenttoitby
theauthenticationserver.
• AuthenticationServer—typicallyaRADIUSauthority,wheretheEnterasysMatrixsystemand
serverhavemutuallyconfiguredknowledgeofoneanother.
Purpose
Toreviewandconfigure802.1XauthenticationforoneormoreportsusingEAPOL(Extensible
AuthenticationProtocol).802.1Xcontrolsnetworkaccessbyenforcinguserauthorizationon