EasyManua.ls Logo

Cisco SF 302-08MP User Manual

Cisco SF 302-08MP
326 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #223 background imageLoading...
Page #223 background image
Configuring Security
802.1X
Cisco Small Business 300 Series Managed Switch Administration Guide 212
16
The 802.1x is an IEEE standard for port based network access control. The 802.1x
framework enables a device (the supplicant) to request port access from a remote
device (authenticator) to which it is connected. Only when the supplicant
requesting port access is authenticated and authorized is the supplicant
permitted to send data to the port. Otherwise, the authenticator discards the
supplicant data unless the data is sent to a Guest VLAN and/or non-authenticated
VLANs.
Authentication of the supplicant is performed by an external RADIUS server
through the authenticator. The authenticator monitors the result of the
authentication.
In the 802.1x standard, a device can be a supplicant and an authenticator at a port
simultaneously, requesting port access and granting port access. However, this
device is only the authenticator, and does not take on the role of a supplicant.
The following varieties of 802.1X exist:
Single session 802.1X:
- A1 —Single-session/single host. In this mode, the switch, as an
authenticator supports one 802.1x session and grants permission to use
the port to the authorized supplicant at a port. All the access by the
other devices received from the same port are denied until the
authorized supplicant is no longer using the port or the access is to the
unauthenticated VLAN or guest VLAN.
- Single session/multiple hosts—This follows the 802.1x standard. In this
mode, the switch as an authenticator allows any device to use a port as
long as it has been granted permission to a supplicant at the port.
Multi-Session 802.1X—Every device (supplicant) connecting to a port
must be authenticated and authorized by the switch (authenticator)
separately in a different 802.1x session. This is the only mode that supports
Dynamic VLAN Assignment (DVA).
Dynamic VLAN Assignment (DVA)
Dynamic VLAN Assignment (DVA) is also referred as RADIUS VLAN Assignment in
this guide. When a port is in Multiple Session mode and is DVA-enabled, the switch
automatically adds the port as an untagged member of the VLAN that is assigned
by the RADIUS server during the authentication process. The switch classifies
untagged packets to the assigned VLAN if the packets are originated from the
devices or ports that are authenticated and authorized.

Table of Contents

Question and Answer IconNeed help?

Do you have a question about the Cisco SF 302-08MP and is the answer not in the manual?

Cisco SF 302-08MP Specifications

General IconGeneral
Product TypeManaged Switch
Number of Ports8
PoE Ports8
PoE Power Budget62 W
PoE Budget62 W
LayerLayer 2
VLANs Supported256
Power SupplyInternal
Ports8 x 10/100 + 2 x Gigabit SFP
Management TypeWeb-based GUI
MAC Address Table Size8K
MAC Address Table8K entries
Jumbo Frame Support9216 bytes
ManagementSNMP
Operating Temperature0 - 40 °C
Storage Temperature-20 - 70 °C
Humidity10% to 90% (non-condensing)

Summary

Viewing Statistics

Managing System Logs

System Log Settings and Remote Logging

Configures system log settings, severity levels, aggregation, and remote SYSLOG servers.

Managing System Files

Firmware and Image Management

Covers upgrading/backing up firmware, language files, and selecting the active boot image.

Configuration and Log Management

Details downloading/backing up configurations or logs, displaying file properties, and copying files.

System Time

System Time Configuration

Explains setting system time manually or dynamically, time zones, and DST.

SNTP Configuration and Authentication

Describes synchronizing the clock with SNTP servers and configuring authentication.

Managing Device Diagnostics

Copper Port Testing

Explains integrated cable tests on copper cables using TDR and DSP-based methods.

Port and VLAN Mirroring

Configures sending copied network packets from ports or VLANs to a monitoring connection.

Configuring Discovery

LLDP Configuration and Management

Enables network managers to troubleshoot via LLDP, edit port settings, and manage network policies.

Port Management

Port Configuration Basics

Configures global and per-port settings like jumbo frames, description, type, status, and speed/duplex.

Link Aggregation and LACP

Explains bundling physical ports into a single logical channel (LAG) for bandwidth and redundancy.

Managing Power-over-Ethernet Devices

PoE Operation and Properties

Explains PoE operation stages, modes, and properties like power limits and traps.

Configuring PoE Power, Priority, and Class

Configures PoE settings per port, including power limits, priority, and class.

VLAN Management

VLAN Basics and Settings

Defines VLANs, explains tagged/untagged members, PVID, GVRP, and VLAN roles.

VLAN Creation and Interface Configuration

Covers creating VLANs, configuring VLAN interface settings (mode, PVID), and defining VLAN membership.

Voice VLAN Configuration

Assigns VoIP traffic to a specific VLAN and configures QoS, and manages Telephony OUIs.

Configuring the Spanning Tree Protocol

Managing MAC Address Tables

Configuring Multicast Forwarding

Configuring IP Information

Configuring Security

802.1X Authentication

Implements port-based network access control using 802.1x, including dynamic VLAN assignment and guest VLANs.

Denial of Service Prevention

Prevents network attacks by filtering packets with specific IP parameters or known malicious content.

Access Control

Configuring Quality of Service

QoS Configuration Workflow

Outlines steps for configuring QoS, including modes, queues, bandwidth, DSCP/CoS mapping, and policies.

QoS Advanced Mode Features

Uses policies, class maps, and policers for per-flow QoS, including DSCP remarking and aggregate policers.

Configuring SNMP

Console Menu Interface

IP Configuration

Configures IPv4/IPv6 addresses, default routes, network settings, and HTTP/HTTPS services.

File Management and Active Image

Manages firmware files, upgrades, backups, and selects the active boot image.

Related product manuals