Comparing EAP relay and EAP termination
Packet exchange
method
EAP relay
EAP termination
EAP relay
Figure 36
shows the basic 802.1X authentication procedure in EAP relay mode, assuming that
EAP-MD5 is used.
Benefits
•
Supports various EAP
authentication methods.
•
The configuration and
processing are simple on the
access device.
Works with any RADIUS server
that supports PAP or CHAP
authentication.
84
Limitations
The RADIUS server must support the
EAP-Message and
Message-Authenticator attributes, and
the EAP authentication method used by
the client.
•
Supports only the following EAP
authentication methods:
MD5-Challenge EAP
authentication.
The username and password
EAP authentication initiated by
an HPE iNode 802.1X client.
•
The processing is complex on the
access device.