116
CN4093 Application Guide for N/OS 8.4
EAPoL Message Exchange
During
authentication,
EAPOL
messages
are
exchanged
between
the
client
and
the
CN4093
authenticator,
while
RADIUS
‐
EAP
messages
are
exchanged
between
the
CN4093
authenticator
and
the
RADIUS
server.
Authentication
is
initiated
by
one
of
the
following
methods:
The
CN4093
authenticator
sends
an
EAP
‐
Request/Identity
packet
to
the
client
The
client
sends
an
EAPOL
‐
Start
frame
to
the
CN4093
authenticator,
which
responds
with
an
EAP
‐
Request/Identity
frame.
The
client
confirms
its
identity
by
sending
an
EAP
‐
Response/Identity
frame
to
the
CN4093
authenticator,
which
forwards
the
frame
encapsulated
in
a
RADIUS
packet
to
the
server.
The
RADIUS
authentication
server
chooses
an
EAP
‐
supported
authentication
algorithm
to
verify
the
client’s
identity,
and
sends
an
EAP
‐
Request
packet
to
the
client
via
the
CN4093
authenticator.
The
client
then
replies
to
the
RADIUS
server
with
an
EAP
‐
Response
containing
its
credentials.
Upon
a
successful
authentication
of
the
client
by
the
server,
the
802.1X
‐
controlled
port
transitions
from
unauthorized
to
authorized
state,
and
the
client
is
allowed
full
access
to
services
through
the
controlled
port.
When
the
client
later
sends
an
EAPOL
‐
Logoff
message
to
the
CN4093
authenticator,
the
port
transitions
from
authorized
to
unauthorized
state.
If
a
client
that
does
not
support
802.1X
connects
to
an
802.1X
‐
controlled
port,
the
CN4093
authenticator
requests
the
client
ʹ
s
identity
when
it
detects
a
change
in
the
operational
state
of
the
port.
The
client
does
not
respond
to
the
request,
and
the
port
remains
in
the
unauthorized
state.
Note:
When
an
802.1X
‐
enabled
client
connects
to
a
port
that
is
not
802.1X
‐
controlled,
the
client
initiates
the
authentication
process
by
sending
an
EAPOL
‐
Start
frame.
When
no
response
is
received,
the
client
retransmits
the
request
for
a
fixed
number
of
times.
If
no
response
is
received,
the
client
assumes
the
port
is
in
authorized
state,
and
begins
sending
frames,
even
if
the
port
is
unauthorized.
EAPoL Port States
The
state
of
the
port
determines
whether
the
client
is
granted
access
to
the
network,
as
follows:
Unauthorized
While
in
this
state
the
port
discards
all
ingress
and
egress
traffic
except
EAP
packets.
Authorized
When
the
client
is
successfully
authenticated,
the
port
transitions
to
the
authorized
state
allowing
all
traffic
to
and
from
the
client
to
flow
normally.
Force
Unauthorized
You
can
configure
this
state
that
denies
all
access
to
the
port.
Force
Authorized
You
can
configure
this
state
that
allows
full
access
to
the
port.
Содержание Flex System Fabric CN4093
Страница 27: ... Copyright Lenovo 2017 27 Part 1 Getting Started ...
Страница 28: ...28 CN4093 Application Guide for N OS 8 4 ...
Страница 58: ...58 CN4093 Application Guide for N OS 8 4 ...
Страница 72: ...72 CN4093 Application Guide for N OS 8 4 ...
Страница 85: ... Copyright Lenovo 2017 85 Part 2 Securing the Switch ...
Страница 86: ...86 CN4093 Application Guide for N OS 8 4 ...
Страница 98: ...98 CN4093 Application Guide for N OS 8 4 ...
Страница 112: ...112 CN4093 Application Guide for N OS 8 4 ...
Страница 136: ...136 CN4093 Application Guide for N OS 8 4 ...
Страница 156: ...156 CN4093 Application Guide for N OS 8 4 ...
Страница 192: ...192 CN4093 Application Guide for N OS 8 4 ...
Страница 228: ...228 CN4093 Application Guide for N OS 8 4 ...
Страница 229: ... Copyright Lenovo 2017 229 Part 4 Advanced Switching Features ...
Страница 230: ...230 CN4093 Application Guide for N OS 8 4 ...
Страница 298: ...298 CN4093 Application Guide for N OS 8 4 ...
Страница 382: ...382 CN4093 Application Guide for N OS 8 4 ...
Страница 392: ...392 CN4093 Application Guide for N OS 8 4 ...
Страница 416: ...416 CN4093 Application Guide for N OS 8 4 ...
Страница 452: ...452 CN4093 Application Guide for N OS 8 4 ...
Страница 466: ...466 CN4093 Application Guide for N OS 8 4 ...
Страница 496: ...496 CN4093 Application Guide for N OS 8 4 ...
Страница 508: ...508 CN4093 Application Guide for N OS 8 4 ...
Страница 510: ...510 CN4093 Application Guide for N OS 8 4 ...
Страница 514: ...514 CN4093 Application Guide for N OS 8 4 ...
Страница 538: ...538 CN4093 Application Guide for N OS 8 4 ...
Страница 539: ... Copyright Lenovo 2017 539 Part 7 Network Management ...
Страница 540: ...540 CN4093 Application Guide for N OS 8 4 ...
Страница 554: ...554 CN4093 Application Guide for N OS 8 4 ...
Страница 576: ...576 CN4093 Application Guide for N OS 8 4 ...
Страница 596: ...596 CN4093 Application Guide for N OS 8 4 ...
Страница 604: ...604 CN4093 Application Guide for N OS 8 4 ...
Страница 609: ... Copyright Lenovo 2017 609 Part 9 Appendices ...
Страница 610: ...610 CN4093 Application Guide for N OS 8 4 ...
Страница 626: ...626 CN4093 Application Guide for N OS 8 4 ...
Страница 633: ......
Страница 634: ...Part Number 00MY375 Printed in USA IP P N 00MY375 ...