The invention provides an access
authentication method for binding a switch port and a host, which is used for solving the problems that a
server is difficult to judge the
correctness of the port and the management complexity is high when a multi-port
client is accessed. According to the method, switch port information (a switch identifier and a port number) is aggregated into a logic user, and the logic user is bound with a
client certificate, so that unified
authentication is realized. A
client can obtain current port information through a
link layer discovery protocol, and submits an
authentication request in the form of'switch identifier-port number '; and the
authentication server carries out
verification according to the stored port information, the logic user and the
certificate public key, and if the connection port does not accord with the binding relationship, the access is refused. The authentication request carries the network port MAC information of the first accessed switch so as to prevent the switch from being counterfeited. According to the technology, the security and flexibility of authentication are effectively improved, and when the
network configuration is changed, only the binding relationship needs to be updated at the
server without modifying the configuration of the client, so that the management burden is remarkably reduced.