3Com 7757 Configuration Manual page 391

3com switch 7750 family
Hide thumbs Also See for 7757:
Table of Contents

Advertisement

The Mechanism of an
802.1x Authentication
System
Encapsulation of EAPoL
Messages
IEEE 802.1x authentication system uses extensible authentication protocol (EAP) to
exchange information between the supplicant system and the authentication
server.
Figure 89 The mechanism of an 802.1x authentication system
EAPOL
Supplicant system
PAE
EAP protocol packets transmitted between the supplicant system and the
authenticator system are encapsulated as EAPoL packets.
EAP protocol packets transmitted between the supplicant system PAE and the
RADIUS server can either be encapsulated as EAPoR (EAP over RADIUS) packets
or be terminated at system PAEs (The system PAEs then communicate with
RADIUS servers through PAP (password authentication protocol) or CHAP
(challenge-handshake authentication protocol) protocol packets.)
When a supplicant system passes the authentication, the authentication server
passes the information about the supplicant system to the authenticator
system. The authenticator system in turn determines the state (authorized or
unauthorized) of the controlled port according to the instructions (accept or
reject) received from the RADIUS server.
The format of an EAPoL packet
EAPoL is a packet encapsulation format defined in 802.1x. To enable EAP protocol
packets to be transmitted between supplicant systems and authenticator systems
through LANs, EAP protocol packets are encapsulated in EAPoL format. The
following figure illustrates the structure of an EAPoL packet.
Figure 90 The format of an EAPoL packet
0
7
PAE Ethernet type
Protocol version
Length
Packet body
In an EAPoL packet:
The PAE Ethernet type field holds the protocol identifier. The identifier for
802.1x is 0x888E.
The Protocol version field holds the version of the protocol supported by the
sender of the EAPoL packet.
The Type field can be one of the following:
00: Indicates that the packet is an EAP-packet, which carries authentication
information.
01: Indicates that the packet is an EAPoL-start packet, which initiates
authentication.
RADIUS
Authenticator system
PAE
15
2
Type
4
6
N
Introduction to 802.1x
391
Authentication server
system

Advertisement

Table of Contents
loading

This manual is also suitable for:

775077587754

Table of Contents