Operation Manual – 802.1x and System Guard
H3C S3100-52P Ethernet switch
Chapter 1 802.1x Configuration
1-6
shows the format of the Data field of a Request packet or a Response
packet.
Figure 1-5
The format of the Data field of a Request packet or a Response packet
z
The Type field indicates the EAP authentication type. A value of 1 indicates
Identity and that the packet is used to query the identity of the peer. A value of 4
represents MD5-Challenge (similar to PPP CHAP) and indicates that the packet
includes query information.
z
The Type Date field differs with types of Request and Response packets.
III. Newly added fields for EAP authentication
Two fields, EAP-message and Message-authenticator, are added to a RADIUS
protocol packet for EAP authentication. (Refer to the Introduction to RADIUS protocol
section in the
AAA Operation
for information about the format of a RADIUS protocol
packet.)
The EAP-message field, whose format is shown in
, is used to encapsulate
EAP packets. The maximum size of the string field is 253 bytes. EAP packets with their
size larger than 253 bytes are fragmented and are encapsulated in multiple
EAP-message fields. The type code of the EAP-message field is 79.
Figure 1-6
The format of an EAP-message field
The Message-authenticator field, whose format is shown in
, is used to
prevent unauthorized interception to access requesting packets during authentications
using CHAP, EAP, and so on. A packet with the EAP-message field must also have the
Message-authenticator field. Otherwise, the packet is regarded as invalid and is
discarded.
Figure 1-7
The format of an Message-authenticator field