114
CN4093 Application Guide for N/OS 8.4
Extensible Authentication Protocol over LAN
Enterprise
NOS
can
provide
user
‐
level
security
for
its
ports
using
the
IEEE
802.1X
protocol,
which
is
a
more
secure
alternative
to
other
methods
of
port
‐
based
network
access
control.
Any
device
attached
to
an
802.1X
‐
enabled
port
that
fails
authentication
is
prevented
access
to
the
network
and
denied
services
offered
through
that
port.
The
802.1X
standard
describes
port
‐
based
network
access
control
using
Extensible
Authentication
Protocol
over
LAN
(EAPoL).
EAPoL
provides
a
means
of
authenticating
and
authorizing
devices
attached
to
a
LAN
port
that
has
point
‐
to
‐
point
connection
characteristics
and
of
preventing
access
to
that
port
in
cases
of
authentication
and
authorization
failures.
EAPoL
is
a
client
‐
server
protocol
that
has
the
following
components:
Supplicant
or
Client
The
Supplicant
is
a
device
that
requests
network
access
and
provides
the
required
credentials
(user
name
and
password)
to
the
Authenticator
and
the
Authenticator
Server.
Authenticator
The
Authenticator
enforces
authentication
and
controls
access
to
the
network.
The
Authenticator
grants
network
access
based
on
the
information
provided
by
the
Supplicant
and
the
response
from
the
Authentication
Server.
The
Authenticator
acts
as
an
intermediary
between
the
Supplicant
and
the
Authentication
Server:
requesting
identity
information
from
the
client,
forwarding
that
information
to
the
Authentication
Server
for
validation,
relaying
the
server’s
responses
to
the
client,
and
authorizing
network
access
based
on
the
results
of
the
authentication
exchange.
The
CN4093
acts
as
an
Authenticator.
Authentication
Server
The
Authentication
Server
validates
the
credentials
provided
by
the
Supplicant
to
determine
if
the
Authenticator
should
grant
access
to
the
network.
The
Authentication
Server
may
be
co
‐
located
with
the
Authenticator.
The
CN4093
relies
on
external
RADIUS
servers
for
authentication.
Upon
a
successful
authentication
of
the
client
by
the
server,
the
802.1X
‐
controlled
port
transitions
from
unauthorized
to
authorized
state,
and
the
client
is
allowed
full
access
to
services
through
the
port.
When
the
client
sends
an
EAP
‐
Logoff
message
to
the
authenticator,
the
port
will
transition
from
authorized
to
unauthorized
state.
Содержание Flex System Fabric CN4093
Страница 27: ... Copyright Lenovo 2017 27 Part 1 Getting Started ...
Страница 28: ...28 CN4093 Application Guide for N OS 8 4 ...
Страница 58: ...58 CN4093 Application Guide for N OS 8 4 ...
Страница 72: ...72 CN4093 Application Guide for N OS 8 4 ...
Страница 85: ... Copyright Lenovo 2017 85 Part 2 Securing the Switch ...
Страница 86: ...86 CN4093 Application Guide for N OS 8 4 ...
Страница 98: ...98 CN4093 Application Guide for N OS 8 4 ...
Страница 112: ...112 CN4093 Application Guide for N OS 8 4 ...
Страница 136: ...136 CN4093 Application Guide for N OS 8 4 ...
Страница 156: ...156 CN4093 Application Guide for N OS 8 4 ...
Страница 192: ...192 CN4093 Application Guide for N OS 8 4 ...
Страница 228: ...228 CN4093 Application Guide for N OS 8 4 ...
Страница 229: ... Copyright Lenovo 2017 229 Part 4 Advanced Switching Features ...
Страница 230: ...230 CN4093 Application Guide for N OS 8 4 ...
Страница 298: ...298 CN4093 Application Guide for N OS 8 4 ...
Страница 382: ...382 CN4093 Application Guide for N OS 8 4 ...
Страница 392: ...392 CN4093 Application Guide for N OS 8 4 ...
Страница 416: ...416 CN4093 Application Guide for N OS 8 4 ...
Страница 452: ...452 CN4093 Application Guide for N OS 8 4 ...
Страница 466: ...466 CN4093 Application Guide for N OS 8 4 ...
Страница 496: ...496 CN4093 Application Guide for N OS 8 4 ...
Страница 508: ...508 CN4093 Application Guide for N OS 8 4 ...
Страница 510: ...510 CN4093 Application Guide for N OS 8 4 ...
Страница 514: ...514 CN4093 Application Guide for N OS 8 4 ...
Страница 538: ...538 CN4093 Application Guide for N OS 8 4 ...
Страница 539: ... Copyright Lenovo 2017 539 Part 7 Network Management ...
Страница 540: ...540 CN4093 Application Guide for N OS 8 4 ...
Страница 554: ...554 CN4093 Application Guide for N OS 8 4 ...
Страница 576: ...576 CN4093 Application Guide for N OS 8 4 ...
Страница 596: ...596 CN4093 Application Guide for N OS 8 4 ...
Страница 604: ...604 CN4093 Application Guide for N OS 8 4 ...
Страница 609: ... Copyright Lenovo 2017 609 Part 9 Appendices ...
Страница 610: ...610 CN4093 Application Guide for N OS 8 4 ...
Страница 626: ...626 CN4093 Application Guide for N OS 8 4 ...
Страница 633: ......
Страница 634: ...Part Number 00MY375 Printed in USA IP P N 00MY375 ...