12.07.2015 Views

TL-SL3428_V3_User_Guide - TP-Link

TL-SL3428_V3_User_Guide - TP-Link

TL-SL3428_V3_User_Guide - TP-Link

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

In this mode, packet transmission is terminated at authenticator systems and the EAP packets aremapped into RADIUS packets. Authentication and accounting are accomplished through RADIUSprotocol.In this mode, PAP or CHAP is employed between the switch and the RADIUS server. This switchsupports the PAP terminating mode. The authentication procedure of PAP is illustrated in thefollowing figure.Supplicant SystemEAPSwitchRADIUSAuthentication ServerEAPOL-StartEAP-Request/IdentityEAP-Response/IdentityEAP-RequestEAP-ResponseRADIUS-Access-RequestEAP-SuccessRADIUS-Access-AcceptFigure 11-19 PAP Authentication ProcedureIn PAP mode, the switch encrypts the password and sends the user name, therandomly-generated key, and the supplicant system-encrypted password to the RADIUS server forfurther authentication. Whereas the randomly-generated key in EAP-MD5 relay mode is generatedby the authentication server, and the switch is responsible to encapsulate the authenticationpacket and forward it to the RADIUS server.‣ 802.1X TimerIn 802.1 x authentication, the following timers are used to ensure that the supplicant system, theswitch, and the RADIUS server interact in an orderly way:(1) Supplicant system timer (Supplicant Timeout): This timer is triggered by the switchafter the switch sends a request packet to a supplicant system. The switch will resend therequest packet to the supplicant system if the supplicant system fails to respond in thespecified timeout period.(2) RADIUS server timer (Server Timeout): This timer is triggered by the switch after theswitch sends an authentication request packet to RADIUS server. The switch will resendthe authentication request packet if the RADIUS server fails to respond in the specifiedtimeout period.(3) Quiet-period timer (Quiet Period): This timer sets the quiet-period. When a supplicantsystem fails to pass the authentication, the switch quiets for the specified period before itprocesses another authentication request re-initiated by the supplicant system.‣ Guest VLANGuest VLAN function enables the supplicants that do not pass the authentication to access thespecific network resource.By default, all the ports connected to the supplicants belong to a VLAN, i.e. Guest VLAN. <strong>User</strong>sbelonging to the Guest VLAN can access the resources of the Guest VLAN without being160

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!