70
Figure 32
802.1X authentication procedure in EAP termination mode
EAPOL
RADIUS
(1) EAPOL-Start
(2) EAP-Request / Identity
(3) EAP-Response / Identity
(4) EAP-Request / MD5 challenge
(8) EAP-Success
(5) EAP-Response / MD5 challenge
(9) EAP-Request/Identity
(10) EAP-Response/Identity
(11) EAPOL-Logoff
...
Client
Device
Authentication server
Port authorized
Port unauthorized
(6) RADIUS Access-Request
(CHAP-Response/MD5 challenge)
(7) RADIUS Access-Accept
(CHAP-Success)
(14) EAP-Failure
In EAP termination mode, it is the network access device rather than the authentication server generates
an MD5 challenge for password encryption (see Step 4). The network access device then sends the MD5
challenge together with the username and encrypted password in a standard RADIUS packet to the
RADIUS server.