LIP-9071
iPKTS
User Guide
90
• Authenticator – a PAE that facilities the authentication of the supplicant. For example, the switch as an
authenticator PAE that controls the physical access to the network based on the
authentication status of a supplicant.
• Authentication server – a PAE, typically a Remote Authentication Dial-In User Service (RADIUS) server that
actually provides authentication service.
The 802.1X protocol makes use of Extensible Authentication Protocol (EAP) messages. The protocol in 802.1X is
called EAP encapsulation over LANs (EAPOL). The Authenticator becomes the middleman for relaying EAP
received in 802.1X packets to an authentication server by using the RADIUS format to carry the EAP information.
1. Supplicant sends EAPOL-Start frame to Authenticator.
2. Authenticator sends EAP-Request/Identity packet to Supplicant.
3. Supplicant sends EAP-Response/Identity packet includes User ID to Authenticator.
4. Authenticator sends it as a RADIUS Access-Request packet to Authentication Server.
5. Authentication Server sends RADIUS Access-Challenge packet to Authenticator to decide the EAP
Method.
6. If Authentication Server and Supplicant agree with EAP Method, exchange EAP Request and
Response between Authentication Server and Supplicant through the Authenticator.
7. Authentication Server sends EAP-Success (RADIUS Access-Accept) or EAP-Fail (RADIUS Access-
Reject.).
EAPOL-
St t
EAP-
R
t/Id
tit
EAP-
R
/Id
tit
RADIUS Access-
R
t
RADIUS Access-
Ch ll
EAP-Request
MD5
EAP-Response
MD5
RADIUS Access-
R
t
EAP-
S
RADIUS Access-
A
t
EAPOL-
L
ff
Port Authorized
Port Unauthorized
Summary of Contents for LIP-9071
Page 155: ...LIP 9071 iPKTS User Guide 142 ...