如下內容,是《
原書1179頁,能夠把人看到吐血而死。
之因此翻譯這個,是由於目前國內介紹到思科交換機的這個功能的中文文獻(指公開文獻)爲0.000???。能夠說,基本無人翻譯介紹過。
而思科的IEEE 802.1x協議的實現,又與目前國內華爲、銳捷、神州數碼等廠商實現的細節有很大不一樣。本身以前作某些配置的時候,徹底被誤導。以致於。。。。。。。
你們看看吧,內行看門道,外行人也看看人行道。呵呵
Using IEEE 802.1x Authentication with MAC Authentication Bypass
基於
You can configure the switch to authorize clients based on the client MAC address (see Figure 9-2 onpage 9-4) by using the MAC authentication bypass feature. For example, you can enable this feature on IEEE 802.1x ports connected to devices such as printers.
你能夠配置交換機使用基於客戶端mac
If IEEE 802.1x authentication times out while waiting for an EAPOL response from the client, the switch tries to authorize the client by using MAC authentication bypass.
若是交換機等待客戶端返回一個IEEE 802.1x
When the MAC authentication bypass feature is enabled on an IEEE 802.1x port, the switch uses the MAC address as the client identity.
當某個IEEE 802.1x
The authentication server has a database of client MAC addresses that are allowed network access. After detecting a client on an IEEE 802.1x port, the switch waits for an Ethernet packet from the client. The switch sends the authentication server a RADIUS-access/request frame with a username and password based on the MAC address. If authorization succeeds, the switch grants the client access to the network. If authorization fails, the switch assigns the port to the guest VLAN if one is configured.
交換機檢測到某個客戶端鏈接到IEEE 802.1x
If an EAPOL packet is detected on the interface during the lifetime of the link, the switch determines that the device connected to that interface is an IEEE 802.1x-capable supplicant and uses IEEE 802.1x authentication (not MAC authentication bypass) to authorize the interface. EAPOL history is cleared if the interface link status goes down.
若是在端口鏈接過程當中,(mac
If the switch already authorized a port by using MAC authentication bypass and detects an IEEE 802.1x supplicant, the switch does not unauthorize the client connected to the port. When re-authentication occurs, the switch uses IEEE 802.1x authentication as the preferred re-authentication process if the previous session ended because the Termination-Action RADIUS attribute value is DEFAULT.
使用基於mac
Clients that were authorized with MAC authentication bypass can be re-authenticated. The re-authentication process is the same as that for clients that were authenticated with IEEE 802.1x. During re-authentication, the port remains in the previously assigned VLAN. If re-authentication is successful, the switch keeps the port in the same VLAN. If re-authentication fails, the switch assigns the port to the guest VLAN, if one is configured.
採用基於mac
If re-authentication is based on the Session-Timeout RADIUS attribute (Attribute[27]) and the Termination-Action RADIUS attribute (Attribute [29]) and if the Termination-Action RADIUS attribute (Attribute [29]) action is Initialize, (the attribute value is DEFAULT), the MAC authentication bypass session ends, and connectivity is lost during re-authentication. If MAC authentication bypass is enabled and the IEEE 802.1x authentication times out, the switch uses the MAC authentication bypass feature to initiate re-authorization. For more information about these AV pairs, see RFC 3580, 「IEEE 802.1X Remote Authentication Dial In User Service (RADIUS) Usage Guidelines.」
若是配置重認證的發起是基於RADIUS
重認證發起後,一樣須要一個IEEE 802.1x
MAC authentication bypass interacts with the features:
基於mac
●你只可以在一個已經啓用了IEEE 802.1x
●若是配置了Guest VLAN
●基於mac
●關於端口安全的相關內容,請參考「Using IEEE 802.1x Authentication with Port Security」
●關於Voice VLAN
●配置了基於mac
●IEEE802.1x
●配置了基於mac
? IEEE 802.1x authentication—You can enable MAC authentication bypass only if IEEE 802.1x authentication is enabled on the port.
? Guest VLAN—If a client has an invalid MAC address identity, the switch assigns the client to a guest VLAN if one is configured.
? Restricted VLAN—This feature is not supported when the client connected to an IEEE 802.lx port is authenticated with MAC authentication bypass.
? Port security—See the 「Using IEEE 802.1x Authentication with Port Security」 section on page 9-15.
? Voice VLAN—See the 「Using IEEE 802.1x Authentication with Voice VLAN Ports」 section on page 9-15.
? VLAN Membership Policy Server (VMPS)—IEEE802.1x and VMPS are mutually exclusive.
? Private VLAN—You can assign a client to a private VLAN.
? Network admission control (NAC) Layer 2 IP validation—
============暫不提供轉載==========數據庫