![SNR S2940-8G-v2 Скачать руководство пользователя страница 306](http://html1.mh-extra.com/html/snr/s2940-8g-v2/s2940-8g-v2_configuration-manual_1310630306.webp)
SNR S2940-8G-v2 Switch Configuration Guide
802.1x Configuration
Supplicant PAE
Services offered
by Authenticator s
system
Authenticator
PAE
Supplicant system
Authenticator system
Authentication
server
Authentication
server system
Port
unauthorized
LAN / WLAN
EAP protocol
exchanges
carried in higher
layer protocol
Figure 45.1: The Authentication Structure of 802.1x
• The authentication server system is an entity to provide authentication service for authentica-
tor systems. The authentication server system is used to authenticate and authorize users,
as well as does fee-counting, and usually is a RADIUS (Remote Authentication Dial-In User
Service) server, which can store the relative user information, including username, password
and other parameters such as the VLAN and ports which the user belongs to.
The three entities above concerns the following basic concepts: PAE of the port, the controlled
ports and the controlled direction.
1. PAE
PAE (Port Access Entity) is the entity to implement the operation of algorithms and protocols.
• The PAE of the supplicant system is supposed to respond the authentication request from
the authenticator systems and submit user's authentication information to the authenticator
system. It can also send authentication request and off-line request to authenticator.
• The PAE of the authenticator system authenticates the supplicant systems needing to access
the LAN via the authentication server system, and deal with the authenticated/unauthenticated
state of the controlled port according to the result of the authentication. The authenticated
state means the user is allowed to access the network resources, the unauthenticated state
means only the EAPOL messages are allowed to be received and sent while the user is
forbidden to access network resources.
2. Controlled/uncontrolled ports
The authenticator system provides ports to access the LAN for the supplicant systems. These
ports can be divided into two kinds of logical ports: controlled ports and uncontrolled ports.
• The uncontrolled port is always in bi-directionally connected status, and mainly used to trans-
mit EAPOL protocol frames, to guarantee that the supplicant systems can always send or
receive authentication messages.
• The controlled port is in connected status authenticated to transmit service messages. When
unauthenticated, no message from supplicant systems is allowed to be received.
• The controlled and uncontrolled ports are two parts of one port, which means each frame
reaching this port is visible on both the controlled and uncontrolled ports.
306
Содержание S2940-8G-v2
Страница 11: ...SNR S2940 8G v2 Switch Configuration Guide Part I Basic Management Configuration 11...
Страница 46: ...SNR S2940 8G v2 Switch Configuration Guide Part II Port Configuration 46...
Страница 123: ...SNR S2940 8G v2 Switch Configuration Guide Part III VLAN and MAC Table Configuration 123...
Страница 164: ...SNR S2940 8G v2 Switch Configuration Guide Part IV MSTP Configuration 164...
Страница 176: ...SNR S2940 8G v2 Switch Configuration Guide Part V QoS and Flow based Redirection Configuration 176...
Страница 198: ...SNR S2940 8G v2 Switch Configuration Guide Part VI L3 Forward and ARP Configuration 198...
Страница 218: ...SNR S2940 8G v2 Switch Configuration Guide Part VII DHCP Configuration 218...
Страница 257: ...SNR S2940 8G v2 Switch Configuration Guide Part VIII Multicast Protocol 257...
Страница 278: ...SNR S2940 8G v2 Switch Configuration Guide Part IX Security Function Configuration 278...
Страница 376: ...SNR S2940 8G v2 Switch Configuration Guide Part X Reliability Configuration 376...
Страница 395: ...SNR S2940 8G v2 Switch Configuration Guide Part XI Flow Monitor Configuration 395...
Страница 403: ...SNR S2940 8G v2 Switch Configuration Guide Part XII Network Time Management Configuration 403...
Страница 411: ...SNR S2940 8G v2 Switch Configuration Guide Part XIII Debugging and Diagnosis 411...