Configuration Guide
802.1x Configuration
Supplicant:
The
supplicant
is a role played by the end user, usually a PC. It requests for the access to network services and
acknowledges the request packets from the authenticator. The supplicant must run the IEEE 802.1x client. Currently, the
most popular one is the IEEE802.1x client carried by Windows XP. In addition, we have also launched the STAR
Supplicant software compliant of this standard.
Authenticator:
The
authenticator
is usually an access device like the switch. The responsibility of the device is to control the connection
status between client and the network according to the current authentication status of that client. Between the client and
server, this device plays the role of a mediator, which requests the client for username, verifies the authentication
information from the server, and forwards it to the client. Therefore, the switch acts as both the IEEE802.1x authenticator
and the RADIUS Client, so it is referred to as the network access server (NAS). It encapsulates the acknowledgement
received from the client into the RADIUS format packets and forwards them to the RADIUS Server, while resolving the
information received from the RADIUS Server and forwards the information to the client.
The device acting as the authenticator has two types of ports: controlled Port and uncontrolled Port. The users connected
to a controlled port can only access network resources after passing the authentication, while those connected to an
uncontrolled port can directly access network resources without authentication. We can control users by simply
connecting them to a controlled port. On the other hand, the uncontrolled port is used to connect the authentication server,
for ensuring normal communication between the server and switch.
Authentication server:
The
authentication server
is usually an
RADIUS
server, which works with the authenticator to provide users with
authentication services. The authentication server saves the user name and password and related authorization
information. One server can provide authentication services for multiple authenticators, thus allowing centralized
management of users. The authentication server also manages the accounting data from the authenticator. Our 802.1x
device is fully compatible with the standard Radius Server, for example, the Radius Server carried on Microsoft Win2000
Server and the Free Radius Server on Linux.
Authentication Initiation and Packet Interaction During Authentication
The supplicant and the authenticator exchange information by EAPOL protocol, while the authenticator and authentication
server exchange information by RADIUS protocol, completing the authentication process with such a conversion. The
EAPOL protocol is encapsulated on the MAC layer, with the type number of 0x888E. In addition, the standard has
Содержание RG-S2900G-E Series
Страница 1: ...RG S2900G E Series Switch RGOS Configuration Guide Release 10 4 2b12 p1 ...
Страница 91: ...Configuration Guide Configuring PoE Configuration ...
Страница 133: ...Configuration Guide EEE Configuration ...
Страница 319: ...Configuration Guide QinQ Configuration ...
Страница 408: ......
Страница 409: ...IP Routing Configuration 1 Static Route Configuration ...
Страница 412: ......
Страница 413: ...Multicast Configuration 1 IGMP Snooping Configuration 2 MLD Snooping Configuration ...
Страница 621: ...Configuration Guide CPU Protection Configuration udp helper 180 4 dhcp client 180 4 lacp 180 4 ...
Страница 757: ......
Страница 758: ...ACL QoS Configuration 1 Access Control List Configuration 2 QoS Configuration ...
Страница 801: ...Reliability Configuration 1 RLDP Configuration 2 TPP Configuration 3 SEM Configuration ...
Страница 901: ...Configuration Guide ERSPAN Configuration ...
Страница 902: ...Web based Configuration 1 Web based Configuration ...