116
NE2552E Application Guide for ENOS 8.4
EAPoL Message Exchange
During
authentication,
EAPOL
messages
are
exchanged
between
the
client
and
the
NE2552E
authenticator,
while
RADIUS
‐
EAP
messages
are
exchanged
between
the
NE2552E
authenticator
and
the
RADIUS
server.
Authentication
is
initiated
by
one
of
the
following
methods:
The
NE2552E
authenticator
sends
an
EAP
‐
Request/Identity
packet
to
the
client
The
client
sends
an
EAPOL
‐
Start
frame
to
the
NE2552E
authenticator,
which
responds
with
an
EAP
‐
Request/Identity
frame.
The
client
confirms
its
identity
by
sending
an
EAP
‐
Response/Identity
frame
to
the
NE2552E
authenticator,
which
forwards
the
frame
encapsulated
in
a
RADIUS
packet
to
the
server.
The
RADIUS
authentication
server
chooses
an
EAP
‐
supported
authentication
algorithm
to
verify
the
client’s
identity,
and
sends
an
EAP
‐
Request
packet
to
the
client
via
the
NE2552E
authenticator.
The
client
then
replies
to
the
RADIUS
server
with
an
EAP
‐
Response
containing
its
credentials.
Upon
a
successful
authentication
of
the
client
by
the
server,
the
802.1X
‐
controlled
port
transitions
from
unauthorized
to
authorized
state,
and
the
client
is
allowed
full
access
to
services
through
the
controlled
port.
When
the
client
later
sends
an
EAPOL
‐
Logoff
message
to
the
NE2552E
authenticator,
the
port
transitions
from
authorized
to
unauthorized
state.
If
a
client
that
does
not
support
802.1X
connects
to
an
802.1X
‐
controlled
port,
the
NE2552E
authenticator
requests
the
client
ʹ
s
identity
when
it
detects
a
change
in
the
operational
state
of
the
port.
The
client
does
not
respond
to
the
request,
and
the
port
remains
in
the
unauthorized
state.
Note:
When
an
802.1X
‐
enabled
client
connects
to
a
port
that
is
not
802.1X
‐
controlled,
the
client
initiates
the
authentication
process
by
sending
an
EAPOL
‐
Start
frame.
When
no
response
is
received,
the
client
retransmits
the
request
for
a
fixed
number
of
times.
If
no
response
is
received,
the
client
assumes
the
port
is
in
authorized
state,
and
begins
sending
frames,
even
if
the
port
is
unauthorized.
EAPoL Port States
The
state
of
the
port
determines
whether
the
client
is
granted
access
to
the
network,
as
follows:
Unauthorized
While
in
this
state
the
port
discards
all
ingress
and
egress
traffic
except
EAP
packets.
Authorized
When
the
client
is
successfully
authenticated,
the
port
transitions
to
the
authorized
state
allowing
all
traffic
to
and
from
the
client
to
flow
normally.
Force
Unauthorized
You
can
configure
this
state
that
denies
all
access
to
the
port.
Force
Authorized
You
can
configure
this
state
that
allows
full
access
to
the
port.
Summary of Contents for ThinkSystem NE2552E
Page 27: ... Copyright Lenovo 2018 27 Part 1 Getting Started ...
Page 28: ...28 NE2552E Application Guide for ENOS 8 4 ...
Page 70: ...70 NE2552E Application Guide for ENOS 8 4 ...
Page 85: ... Copyright Lenovo 2018 85 Part 2 Securing the Switch ...
Page 86: ...86 NE2552E Application Guide for ENOS 8 4 ...
Page 112: ...112 NE2552E Application Guide for ENOS 8 4 ...
Page 134: ...134 NE2552E Application Guide for ENOS 8 4 ...
Page 154: ...154 NE2552E Application Guide for ENOS 8 4 ...
Page 194: ...194 NE2552E Application Guide for ENOS 8 4 ...
Page 218: ...218 NE2552E Application Guide for ENOS 8 4 ...
Page 234: ...234 NE2552E Application Guide for ENOS 8 4 ...
Page 238: ...238 NE2552E Application Guide for ENOS 8 4 ...
Page 239: ... Copyright Lenovo 2018 239 Part 4 Advanced Switching Features ...
Page 240: ...240 NE2552E Application Guide for ENOS 8 4 ...
Page 242: ...242 NE2552E Application Guide for ENOS 8 4 ...
Page 278: ...278 NE2552E Application Guide for ENOS 8 4 ...
Page 284: ...284 NE2552E Application Guide for ENOS 8 4 ...
Page 314: ...314 NE2552E Application Guide for ENOS 8 4 ...
Page 338: ...338 NE2552E Application Guide for ENOS 8 4 ...
Page 374: ...374 NE2552E Application Guide for ENOS 8 4 ...
Page 388: ...388 NE2552E Application Guide for ENOS 8 4 ...
Page 418: ...418 NE2552E Application Guide for ENOS 8 4 ...
Page 430: ...430 NE2552E Application Guide for ENOS 8 4 ...
Page 432: ...432 NE2552E Application Guide for ENOS 8 4 ...
Page 436: ...436 NE2552E Application Guide for ENOS 8 4 ...
Page 460: ...460 NE2552E Application Guide for ENOS 8 4 ...
Page 461: ... Copyright Lenovo 2018 461 Part 7 Network Management ...
Page 462: ...462 NE2552E Application Guide for ENOS 8 4 ...
Page 476: ...476 NE2552E Application Guide for ENOS 8 4 ...
Page 498: ...498 NE2552E Application Guide for ENOS 8 4 ...
Page 520: ...520 NE2552E Application Guide for ENOS 8 4 ...
Page 534: ...534 NE2552E Application Guide for ENOS 8 4 ...
Page 536: ...536 NE2552E Application Guide for ENOS 8 4 ...
Page 544: ...544 NE2552E Application Guide for ENOS 8 4 ...
Page 549: ... Copyright Lenovo 2018 549 Part 9 Appendices ...
Page 550: ...550 NE2552E Application Guide for ENOS 8 4 ...
Page 566: ...566 NE2552E Application Guide for ENOS 8 4 ...
Page 572: ...572 NE2552E Application Guide for ENOS 8 4 ...
Page 573: ......
Page 574: ...Part Number 01KN246 Printed in USA IP P N 01KN246 ...