![H3C S5500-SI Series Скачать руководство пользователя страница 594](http://html2.mh-extra.com/html/h3c/s5500-si-series/s5500-si-series_operation-manual_3758650594.webp)
1-6
Unsolicited triggering of a client
A client initiates authentication by sending an EAPOL-Start frame to the device. The destination
address of the frame is 01-80-C2-00-00-03, the multicast address specified by the IEEE 802.1X
protocol.
Some devices in the network may not support multicast packets with the above destination address,
causing the authentication device unable to receive the authentication request of the client. To solve the
problem, the device also supports EAPOL-Start frames whose destination address is a broadcast MAC
address. In this case, the H3C iNode 802.1X client is required.
Unsolicited triggering of the device
The device can trigger authentication by sending EAP-Request/Identity packets to unauthenticated
clients periodically (every 30 seconds by default). This method can be used to authenticate clients
which cannot send EAPOL-Start frames and therefore cannot trigger authentication, for example, the
802.1X client provided by Windows XP.
Authentication Process of 802.1X
An 802.1X device communicates with a remotely located RADIUS server in two modes: EAP relay and
EAP termination. The following description takes the EAP relay as an example to show the 802.1X
authentication process.
EAP relay
EAP relay is an IEEE 802.1X standard mode. In this mode, EAP packets are carried in an upper layer
protocol, such as RADIUS, so that they can go through complex networks and reach the authentication
server. Generally, EAP relay requires that the RADIUS server support the EAP attributes of
EAP-Message and Message-Authenticator, which are used to encapsulate EAP packets and protect
RADIUS packets carrying the EAP-Message attribute respectively.
shows the message exchange procedure with EAP-MD5.
Содержание S5500-SI Series
Страница 161: ...3 10 GigabitEthernet1 0 1 2 MANUAL...
Страница 220: ...1 7 Clearing ARP entries from the ARP table may cause communication failures...
Страница 250: ...3 3 SwitchB system view SwitchB interface vlan interface 1 SwitchB Vlan interface1 ip address dhcp alloc...
Страница 310: ...i Table of Contents 1 Dual Stack Configuration 1 1 Dual Stack Overview 1 1 Configuring Dual Stack 1 1...
Страница 331: ...1 7 1 1 ms 1 ms 1 ms 1 1 6 1 2 1 ms 1 ms 1 ms 1 1 4 1 3 1 ms 1 ms 1 ms 1 1 2 2 Trace complete...
Страница 493: ...2 8...
Страница 1111: ...1 10 Installing patches Installation completed and patches will continue to run after reboot...