C h a p t e r
12
DOT1X Configuration
Table of Contents
DOT1x Overview ............................................................. 129
Configuring DOT1X .......................................................... 130
DOT1X Configuration Example........................................... 137
DOT1X Maintenance and Diagnosis .................................... 140
DOT1x Overview
DOT1X, IEEE 802.1x, is a port-based network access control pro-
tocol. It optimizes the authentication mode and authentication
architecture and solves the problems caused by traditional PPPoE
and Web/Portal authentication modes, therefore it is more suitable
for the broadband Ethernet.
IEEE 802.1x protocol architecture contains three major parts:
Supplicant System, Authenticator System and Authentication
Server System.
1. Generally client system is a user terminal system where client
software is often installed. User originates IEEE802.1x protocol
authentication by booting the client software. To support port-
based access control, the client system needs to support the
Extensible Authentication Protocol Over LAN (EAPOL).
2. Authentication system is network equipment supporting the
IEEE802.1x protocol, such as the switch. The equipment cor-
responds to different user ports (physical port or MAC address,
VLAN and IP of the user equipment) and has two logical ports
composed of the controlled port and uncontrolled port.
�
Uncontrolled port is always in bidirectional connection state
and delivers EAPOL protocol, which ensures the client to
always send or receive authentication.
�
Controlled port opens upon success of the authentication
to deliver network resources and services. The controlled
port modes can be configured as bidirectional controlled
and only transmission controlled to adapt to different ap-
plication environments. If the user fails to pass authentica-
tion, the controlled port is in unauthenticated state and the
user cannot access services offered by the authentication
system.
Controlled port and uncontrolled port in the IEEE 802.1x pro-
tocol are logical concepts and such physical switches are inex-
istent in the equipment. The IEEE 802.1x protocol establishes
Confidential and Proprietary Information of ZTE CORPORATION
129