Signamax 065-7840 24-Port 10/100/1000BaseT/TX Managed Switch
109
Fig. 3-51 shows the procedure of 802.1x authentication. There are steps for
the login based on 802.1x port access control management. The protocol used in
the right side is EAPOL and the left side is EAP.
1.
At the initial stage, the supplicant A is unauthenticated and a port
on the switch acting as an authenticator is in an unauthorized state.
Therefore, the access is blocked at this stage.
2.
Initiating a session: Either the authenticator or the supplicant can
initiate the message exchange. If the supplicant initiates the
process, it sends an EAPOL-start packet to the authenticator PAE
and the authenticator will immediately respond with an EAP-
Request/Identity packet.
3. The
authenticator
always periodically sends EAP-Request/Identity
to the supplicant in order to request the identity it wants to be
authenticated.
4.
If the authenticator doesn’t send an EAP-Request/Identity, the
supplicant will initiate the process by sending EAPOL-Start to the
authenticator.
5.
Next, the Supplicant replies with an EAP-Response/Identity to the
authenticator. The authenticator will embed the user ID into a
Radius-Access-Request command and send it to the authentication
server for confirmation of its identity.
6.
After receiving the Radius-Access-Request, the authentication
server sends a Radius-Access-Challenge to the supplicant to ask
for the input of the user password via the authenticator PAE.
7.
The supplicant will convert the user password into the credential
information in MD5 format and replies with an EAP-Response with
this credential information as well as the specified authentication
algorithm (MD5 or OTP) to the authentication server via the
authenticator PAE. As determined by the value of the type field in
the message PDU, the authentication server knows which algorithm
should be applied to authenticate the credential information, either
EAP-MD5 (Message Digest 5), or EAP-OTP (One Time Password),
or another type of algorithm.
Supplicant A
B
C
Authentication server
Authenticator
Fig. 3-50
Содержание 065-7840
Страница 2: ......
Страница 4: ...Signamax 065 7840 24 Port 10 100 1000BaseT TX Managed Switch ii ...
Страница 7: ...Signamax 065 7840 24 Port 10 100 1000BaseT TX Managed Switch v ...
Страница 9: ...Signamax 065 7840 24 Port 10 100 1000BaseT TX Managed Switch vii ...
Страница 144: ...Signamax 065 7840 24 Port 10 100 1000BaseT TX Managed Switch 134 Fig 4 1 Fig 4 2 065 7840 065 7840 065 7840 065 7840 ...