DES-7200 Configuration Guide Chapter 4 802.1x Configuration
4-64
4.5.4 Application of port-based
1X authentication and IP
authorization
4.5.4.1 Network Topology
Figure15 topology for port-based 1X authentication and IP authorization
4.5.4.2 Networking Requirements
The client accesses network through 802.1x authentication. RADIUS server is the
authentication server. The following application needs must be met:
When the active server fails due to certain reason, the device can automatically submit
authentication request to the next server in the method list.
When a user connected to one port of device passes the authentication, all users
connected to this port will be able to access network freely.
Dynamic user is not allowed to move between multiple authentication ports.
The IP of an authenticated user must be assigned by the RADIUS Server, namely the
authenticated user can only use the IP specified by RADIUS Server to access network.
4.5.4.3 Configuration Tips
Turn on AAA switch and configure the communication between device and RADIUS
SERVER;
Configure 802.1X authentication and configure the device port for client access as
controlled port;