![SNR S2940-8G-v2 Скачать руководство пользователя страница 312](http://html1.mh-extra.com/html/snr/s2940-8g-v2/s2940-8g-v2_configuration-manual_1310630312.webp)
SNR S2940-8G-v2 Switch Configuration Guide
802.1x Configuration
Supplicant
PAE
Authenticator
System PAE
RADIUS
server
EAPOL-Start
EAP-Request/Identity
EAP-Response/Identity
RADIUS Access-Request
(EAP-Response/Identity)
EAP-Request/MD5 Challenge
RADIUS Access-Challenge
(EAP-Request/MD5 Challenge)
EAP-Response/MD5 Challenge
RADIUS Access-Request
(EAP-Response/MD5 Challenge)
EAP-Success
RADIUS Access-Accept
(EAP-Success)
EAPOL
EAPOR
Handshake request packet
[EAP-Request/Identity]
Handshake response packet
{EAP-Response/Identity]
EAPOL-Logoff
...
Port authorized
Port unauthorized
Expiry of the handshake timer
Figure 45.9: the Authentication Flow of 802.1x EAP-MD5
encrypted tunnel established via the certificate of the authentication server. Any kind of authenti-
cation request including EAP, PAP and MS-CHAPV2 can be transmitted within TTLS tunnels.
4. PEAP Authentication Method
EAP-PEAP is brought up by Cisco, Microsoft and RAS Security as a recommended open stan-
dard. It has long been utilized in products and provides very good security. Its design of protocol
and security is similar to that of EAP-TTLS, using a server's PKI certificate to establish a safe TLS
tunnel in order to protect user authentication.
The following figure illustrates the basic operation flow of PEAP authentication method.
EAP Termination Mode
In this mode, EAP messages will be terminated in the access control unit and mapped into RADIUS
messages, which is used to implement the authentication, authorization and fee-counting. The
basic operation flow is illustrated in the next figure.
In EAP termination mode, the access control unit and the RADIUS server can use PAP or
CHAP authentication method. The following figure will demonstrate the basic operation flow using
CHAP authentication method.
312
Содержание S2940-8G-v2
Страница 11: ...SNR S2940 8G v2 Switch Configuration Guide Part I Basic Management Configuration 11...
Страница 46: ...SNR S2940 8G v2 Switch Configuration Guide Part II Port Configuration 46...
Страница 123: ...SNR S2940 8G v2 Switch Configuration Guide Part III VLAN and MAC Table Configuration 123...
Страница 164: ...SNR S2940 8G v2 Switch Configuration Guide Part IV MSTP Configuration 164...
Страница 176: ...SNR S2940 8G v2 Switch Configuration Guide Part V QoS and Flow based Redirection Configuration 176...
Страница 198: ...SNR S2940 8G v2 Switch Configuration Guide Part VI L3 Forward and ARP Configuration 198...
Страница 218: ...SNR S2940 8G v2 Switch Configuration Guide Part VII DHCP Configuration 218...
Страница 257: ...SNR S2940 8G v2 Switch Configuration Guide Part VIII Multicast Protocol 257...
Страница 278: ...SNR S2940 8G v2 Switch Configuration Guide Part IX Security Function Configuration 278...
Страница 376: ...SNR S2940 8G v2 Switch Configuration Guide Part X Reliability Configuration 376...
Страница 395: ...SNR S2940 8G v2 Switch Configuration Guide Part XI Flow Monitor Configuration 395...
Страница 403: ...SNR S2940 8G v2 Switch Configuration Guide Part XII Network Time Management Configuration 403...
Страница 411: ...SNR S2940 8G v2 Switch Configuration Guide Part XIII Debugging and Diagnosis 411...