![Nortel 2526T Configuration Download Page 22](http://html1.mh-extra.com/html/nortel/2526t/2526t_configuration_1707291022.webp)
22
Using security in your network
service such as RADIUS. This security feature works hand-in-hand with
the Radius-based server and thus provides the advantages of remote
authentication to internal LAN clients.
An example follows to show how an Ethernet Routing Switch 2500 Series
reacts when it is configured to the EAPoL security feature and a new
network connection:
•
When the switch finds a new connection in one of its ports, the following
occurs:
1. The switch asks for a User ID of the new client.
2. The User ID is covered by EAPoL, and it passes on to the Radius
server.
3. The response from the Radius server is to ask for a password of
the user.
•
Within the EAPoL packet, the new client forwards a password to the
switch:
— The EAPoL packet is relayed to the Radius server.
— If the Radius server validates the password, the new client is allowed
to access the switch and the network.
The EAPoL-based security is composed of the following terms:
•
Supplicant- the device applying for network access.
•
Authenticator- a software with the main purpose of authorizing the
supplicant who is attached at the other end of the LAN segment.
•
Authentication server- a Radius server that provides authorization
services to an authenticator.
•
Port Access Entity (PAE)- an entity that supports each port to the
Authenticator or Supplicants. In the example above, the authenticator
PAE is present in the switch.
Controlled Port is a switch port with EAPOL based security. The
authenticator communicates with the Supplicant through EAP over LAN
(EAPoL), which is an encapsulation mechanism.
The authenticator PAE encapsulates the EAP through the RADIUS
server packet and sends it to the authentication server. The
authenticator server sends the packet in an exchange that occurs
between the supplicant and authentication server. This exchange
occurs when the EAP message is encapsulated to make it suitable for
the destination of the packet.
The authenticator determines the operational state of the controlled
port. The RADIUS server notifies the authenticator PAE of the success
Nortel Ethernet Routing Switch 2500 Series
Security — Configuration and Management
NN47215-505 (323165-B)
02.01
Standard
4.1
19 November 2007
Copyright © 2007, Nortel Networks
.
Summary of Contents for 2526T
Page 227: ......