ZXDSL 9210 (V3.1) Broadband Universal Access Equipment Technical Manual
6-22
The supplicant PAE may initiate authentication switching and implements
EAPOL-Logoff switching.
6.2.8.3 802.1X Protocol Process
The authentication occurs during system initialization or when the supplicant system is
connected with a port of the authenticator system. Before authentication succeeds, the
system can only gain access to the authentication system for authentication switching;
or it can access the services which are provided by the authenticator system and not
restricted by access control on the authenticator controlled port. Once authentication
succeeds, the supplicant can gain access to all services provided by the controlled port
of the authenticator system. In addition to controlling the authorization status of the
controlled port, the authenticator PAE can request for the supplicant re-authentication
at any time. During the re-authentication, the controlled port keeps the authorization
status; it is converted to the unauthorized status only when re-authentication fails.
When the supplicant needs to terminate the services provided by the authenticator
controlled port, the supplicant PAE can send an EAPOL-Logoff request; the
authenticator PAE will set the controlled port as the unauthorized status. The
authentication system is transparent for the EAPOL packet; it only unpacks the EAP
protocol information from the EAPOL and resends it to the Radius Server according to
an agreed format. The authentication system only opens and closes the port according
to the final authentication result; the user access control can be thus enabled.
Fig. 6.2-9 shows the session flow of authentication switching among the supplicant,
authenticator, and authentication server.