13.07.2015 Views

Administration of the Avaya G350 Media Gateway - Avaya Support

Administration of the Avaya G350 Media Gateway - Avaya Support

Administration of the Avaya G350 Media Gateway - Avaya Support

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Accessing <strong>the</strong> <strong>Avaya</strong> <strong>G350</strong> <strong>Media</strong> <strong>Gateway</strong>802.1x interacts with existing standards to perform its au<strong>the</strong>ntication operation. Specifically, itmakes use <strong>of</strong> Extensible Au<strong>the</strong>ntication Protocol (EAP) messages, encapsulated withinE<strong>the</strong>rnet frames (EAPOL), and EAP over RADIUS for <strong>the</strong> communication between <strong>the</strong>Au<strong>the</strong>nticator and <strong>the</strong> Au<strong>the</strong>ntication Server.Note:Note:The <strong>G350</strong> only supports MD5 EAP type.Configuring 802.1xYou can configure 802.1x on <strong>the</strong> <strong>G350</strong>’s PoE module (MM314). You can configure 802.1x onany <strong>of</strong> <strong>the</strong> MM314 ports except <strong>the</strong> Gigabit E<strong>the</strong>rnet port (port 51).To configure 802.1x:1. Configure RADIUS au<strong>the</strong>ntication on <strong>the</strong> <strong>G350</strong>. For instructions, see RADIUSau<strong>the</strong>ntication on page 40.2. Use <strong>the</strong> set port dot1x port-control command to change <strong>the</strong> 802.1x mode <strong>of</strong> anindividual port. This command must be followed by <strong>the</strong> module and port number, and <strong>the</strong>802.1x mode. The following are <strong>the</strong> possible modes:- force-unauthorize — <strong>the</strong> port is always blocked- auto — whe<strong>the</strong>r <strong>the</strong> port is blocked or open depends on <strong>the</strong> au<strong>the</strong>ntication outcome- force-authorize — <strong>the</strong> port is always open (in forwarding state)By default, all ports are in auto mode. In o<strong>the</strong>r words, all ports are configured to use 802.1xau<strong>the</strong>ntication if it is enabled on <strong>the</strong> <strong>G350</strong>. If a port is not in auto mode, you can use <strong>the</strong>following command to return <strong>the</strong> port to auto mode:<strong>G350</strong>-001(super)# set port dot1x port-control 6/3 autoDone !<strong>G350</strong>-001(super)#3. Use <strong>the</strong> set port dot1x port-control command to configure <strong>the</strong> au<strong>the</strong>nticationmode <strong>of</strong> <strong>the</strong> LAN port connected to <strong>the</strong> RADIUS server as force-authorize. This ensuresthat <strong>the</strong> port remains open at all times, so that it will be able to transmit au<strong>the</strong>nticationrequests to <strong>the</strong> RADIUS server. For example, if port 2 is <strong>the</strong> port that connects to <strong>the</strong>RADIUS server, type <strong>the</strong> following command:<strong>G350</strong>-001(super)# set port dot1x port-control 6/2 force-authorizeDone !<strong>G350</strong>-001(super)#42 <strong>Administration</strong> <strong>of</strong> <strong>the</strong> <strong>Avaya</strong> <strong>G350</strong> <strong>Media</strong> <strong>Gateway</strong>

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!