8.2.3 Legacy Mode
This mode is an operating mode that was provided by the name Dynamic VLAN Mode in AX6000S series, AX3630S,, and AX2430S versions earlier than Ver.10.7. Use this option when you want to apply the Switch to a network that was built using Web authentication function prior to Ver.10.7.
In this mode, the native VLAN is designated as the pre-authentication VLAN, and a MAC VLAN is designated as the post-authentication VLAN. Prior to authentication, the MAC address of the terminal is associated with the pre-authentication VLAN. If authentication succeeds, the switch associates the MAC address with the post-authentication VLAN. For this to work, the following configuration is required:
-
A MAC VLAN must be configured as the post-authentication VLAN
-
An access list must be configured that prohibits unnecessary communication between the pre-authentication and post-authentication VLANs
- <Structure of this section>
(1) Local authentication method
The figure below describes local authentication using an internal Web authentication DB.
|
-
A user of a PC connected via a hub opens a Web browser and accesses the Switch.
-
The Switch compares the user ID and password entered by the user against the user information in the internal Web authentication DB.
-
If authentication succeeds, a page appears on the PC indicating that authentication was successful, and the PC gains membership to the post-authentication VLAN.
-
The authenticated PC is able to access servers in the post-authentication VLAN.
(2) RADIUS authentication-method
The figure below describes RADIUS authentication using a RADIUS server.
|
-
A user of a PC connected via a hub opens a Web browser and accesses the Switch.
-
Authentication takes place by comparing the user ID and password entered by the user against the user information registered on the RADIUS server.
-
If authentication succeeds, a page appears on the PC indicating that authentication was successful, and the PC gains membership to the post-authentication VLAN.
-
The authenticated PC is able to access servers in the post-authentication VLAN.