13.07.2015 Views

Administration of the Avaya G350 Media Gateway - Avaya Support

Administration of the Avaya G350 Media Gateway - Avaya Support

Administration of the Avaya G350 Media Gateway - Avaya Support

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Managing login permissionsTo disable RADIUS au<strong>the</strong>ntication on <strong>the</strong> <strong>G350</strong>, use <strong>the</strong> set radius au<strong>the</strong>nticationdisable command.To display <strong>the</strong> RADIUS parameters, use <strong>the</strong> show radius au<strong>the</strong>ntication command.Shared secrets are not displayed.For additional information on RADIUS configuration and au<strong>the</strong>ntication, go to <strong>the</strong> <strong>Avaya</strong> website at http://www.avaya.com/support, and perform a search for <strong>the</strong> document <strong>Avaya</strong> G700/<strong>G350</strong> RADIUS Configuration Overview.802.1x protocolThe 802.1x protocol is a method for performing au<strong>the</strong>ntication to obtain access to <strong>the</strong> <strong>G350</strong>’sLAN ports. 802.1x provides a means <strong>of</strong> au<strong>the</strong>nticating and authorizing users attached to a LANport and <strong>of</strong> preventing access to that port in cases where <strong>the</strong> au<strong>the</strong>ntication process fails. Youcan enable 802.1x on <strong>the</strong> MM314 media module’s 10/100 E<strong>the</strong>rnet ports.Note:Note: You cannot enable 802.1x on <strong>the</strong> MM314 media module’s Gigabit E<strong>the</strong>rnet port(port 51).The 802.1x protocol defines an interaction between <strong>the</strong> following three entities:● Supplicant — an entity (<strong>the</strong> host) at one end <strong>of</strong> a point-to-point LAN segment that isrequesting au<strong>the</strong>ntication●●Au<strong>the</strong>nticator — an entity (in this case <strong>the</strong> <strong>G350</strong>) at <strong>the</strong> o<strong>the</strong>r end <strong>of</strong> a point-to-point LANsegment that facilitates au<strong>the</strong>ntication <strong>of</strong> <strong>the</strong> SupplicantAu<strong>the</strong>ntication (RADIUS) Server — an entity that provides an au<strong>the</strong>ntication service to <strong>the</strong>Au<strong>the</strong>nticator. The Au<strong>the</strong>ntication Server determines, from <strong>the</strong> credentials provided by <strong>the</strong>Supplicant, whe<strong>the</strong>r <strong>the</strong> Supplicant is authorized to access <strong>the</strong> services provided by <strong>the</strong>Au<strong>the</strong>nticator.How port based au<strong>the</strong>ntication worksThe au<strong>the</strong>ntication procedure is port-based, which means:●●●access control is achieved by enforcing au<strong>the</strong>ntication on connected portsif an endpoint station that connects to a port is not authorized, <strong>the</strong> port state is set to“unauthorized”, which closes <strong>the</strong> port to all trafficas a result <strong>of</strong> an au<strong>the</strong>ntication attempt, <strong>the</strong> port can be ei<strong>the</strong>r in a “blocked” or a“forwarding” stateIssue 3 January 2005 41

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!