Authentication - Planet GS-5220 Series User Manual

L2+ gigabit/10 managed lcd switch
Hide thumbs Also See for GS-5220 Series:
Table of Contents

Advertisement

4.11 Authentication

This section is to control the access to the Managed Switch, including the user access and management control.
The Authentication section contains links to the following main topics:
 IEEE 802.1X Port-based Network Access Control
 MAC-based Authentication
 User Authentication
Overview of 802.1X (Port-Based) Authentication
In the 802.1X-world, the user is called the supplicant, the switch is the authenticator, and the RADIUS server is
the authentication server. The switch acts as the man-in-the-middle, forwarding requests and responses
between the supplicant and the authentication server. Frames sent between the supplicant and the switch are
special 802.1X frames, known as EAPOL (EAP Over LANs) frames. EAPOL frames encapsulate EAP PDUs
(RFC3748). Frames sent between the switch and the RADIUS server are RADIUS packets. RADIUS packets also
encapsulate EAP PDUs together with other attributes like the switch's IP address, name, and the supplicant's
port number on the switch. EAP is very flexible, in that it allows for different authentication methods, like
MD5-Challenge, PEAP, and TLS. The important thing is that the authenticator (the switch) doesn't need to know
which authentication method the supplicant and the authentication server are using, or how many information
exchange frames are needed for a particular method. The switch simply encapsulates the EAP part of the frame
into the relevant type (EAPOL or RADIUS) and forwards it.
When authentication is complete, the RADIUS server sends a special packet containing a success or failure
indication. Besides forwarding this decision to the supplicant, the switch uses it to open up or block traffic on the
switch port connected to the supplicant.
Overview of MAC-based Authentication
Unlike 802.1X, MAC-based authentication is not a standard, but merely a best-practices method adopted by the
industry. In MAC-based authentication, users are called clients, and the switch acts as the supplicant on behalf of
User's Manual of GS-5220 LCD Series
361

Advertisement

Table of Contents
loading

Table of Contents