78
EAP termination
In EAP termination mode, EAP packets are terminated at the device and then repackaged into the PAP or
CHAP attributes of RADIUS and transferred to the RADIUS server for authentication, authorization, and
accounting.
shows the message exchange procedure with CHAP authentication.
Figure 35
Message exchange in EAP termination mode
EAPOL
RADIUS
(1) EAPOL-Start
(2) EAP-Request/Identity
(3) EAP-Response/Identity
(4) EAP-Request/MD5 challenge
(8) EAP-Success
(5) EAP-Response/MD5 challenge
(9) Handshake request
(EAP-Request/Identity )
(10) Handshake response
(EAP-Response / Identity )
(11) EAPOL-Logoff
......
Client
Device
Server
Port authorized
Handshake timer
Port unauthorized
(6) RADIUS Access-Request
(CHAP-Response/MD5 challenge)
(7) RADIUS Access-Accept
(CHAP-Success)
Different from the authentication process in EAP relay mode, it is the device that generates the random
challenge for encrypting the user password information in the EAP termination authentication process
(Step 4). Consequently, the device sends the challenge together with the username and encrypted
password information from the client to the RADIUS server for authentication.