12.03.2015 Views

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

FortiGate Administration Guide - FirewallShop.com

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Configuring 802.1X authentication<br />

Switch (<strong>FortiGate</strong>-224B only)<br />

Configuring 802.1X authentication<br />

<strong>FortiGate</strong>-224B supports device authentication using the IEEE 802.1X standard.<br />

When 802.1X is enabled, no <strong>com</strong>munication, even ARP or DHCP, is permitted<br />

until authentication is successful. Authentication is valid only on one port. If the<br />

device is moved to a different port, it must reauthenticate.<br />

<strong>FortiGate</strong>-224B unit acts as a proxy between the host 802.1X client, called a<br />

supplicant, and the RADIUS server. When the RADIUS server replies with an<br />

authentication success message, the <strong>FortiGate</strong>-224B permits the host device to<br />

access the network.<br />

For information about configuring the 802.1X supplicant, refer to the<br />

documentation for the supplicant. For information about configuring the RADIUS<br />

server, refer to the documentation for the RADIUS server.<br />

You must configure the <strong>FortiGate</strong>-224B unit to access a RADIUS server to<br />

perform authentication before you configure 802.1X authentication. See<br />

“Configuring a RADIUS server” on page 381.<br />

Go to Switch > 802.1X.<br />

Figure 138:802.1X settings<br />

Radius Server<br />

Select the RADIUS authentication server.<br />

If needed, select Create New or go to User > RADIUS to set<br />

up a RADIUS server.<br />

Supplicant Timeout (sec.) Enter the maximum time in seconds that the <strong>FortiGate</strong>-224B<br />

unit waits for a response from the client. The default is 30<br />

seconds.<br />

Server Timeout (sec.)<br />

Max Re-Authentication<br />

Re-Authentication Period<br />

(sec.)<br />

Enter the maximum time in seconds that the <strong>FortiGate</strong>-224B<br />

unit waits for a response from the RADIUS server. The<br />

default is 15 seconds.<br />

Enter the maximum number of in<strong>com</strong>plete authentication<br />

attempts the <strong>FortiGate</strong>-224B unit permits from one client. The<br />

default is 2. After this number of attempts, the client’s status<br />

is unauthorized.<br />

Enter the time period in seconds after which the client must<br />

reauthenticate. The default is 3600 seconds.<br />

The table shows the authenticated clients.<br />

Port<br />

The switch port to which the client is connected.<br />

MAC Address<br />

The client’s MAC address.<br />

PAE State<br />

Port Access Entity authentication status<br />

BE State<br />

Back End state<br />

Status<br />

Port status: Authorized or Unauthorized<br />

<strong>FortiGate</strong> Version 3.0 MR5 <strong>Administration</strong> <strong>Guide</strong><br />

226 01-30005-0203-20070830

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!