3Com S7906E Configuration Manual page 1881

S7900e family release 6600 series
Hide thumbs Also See for S7906E:
Table of Contents

Advertisement

Figure 1-8 802.1X authentication procedure in EAP relay mode
Client
EAPOL
EAPOL-Start
EAP-Request / Identity
EAP-Response / Identity
EAP-Request / MD5 challenge
EAP-Response / MD5 challenge
EAP-Success
Handshake request
( EAP-Request / Identity )
Handshake response
( EAP-Response / Identity )
......
EAPOL-Logoff
2)
When a user launches the 802.1X client software and enters the registered username and
password, the 802.1X client software generates an EAPOL-Start packet and sends it to the device
to initiate an authentication process.
3)
Upon receiving the EAPOL-Start packet, the device responds with an EAP-Request/Identity packet
for the username of the client.
4)
When the client receives the EAP-Request/Identity packet, it encapsulates the username in an
EAP-Response/Identity packet and sends the packet to the device.
5)
Upon receiving the EAP-Response/Identity packet, the device relays the packet in a RADIUS
Access-Request packet to the authentication server.
6)
When receiving the RADIUS Access-Request packet, the RADIUS server compares the identify
information against its user information database to obtain the corresponding password
information. Then, it encrypts the password information using a randomly generated challenge,
and sends the challenge information through a RADIUS Access-Challenge packet to the device.
7)
After receiving the RADIUS Access-Challenge packet, the device relays the contained
EAP-Request/MD5 Challenge packet to the client.
8)
When receiving the EAP-Request/MD5 Challenge packet, the client uses the offered challenge to
encrypt the password part (this process is not reversible), creates an EAP-Response/MD5
Challenge packet, and then sends the packet to the device.
9)
After receiving the EAP-Response/MD5 Challenge packet, the device relays the packet in a
RADIUS Access-Request packet to the authentication server.
Device
RADIUS Access-Request
(EAP-Response / Identity)
RADIUS Access-Challenge
(EAP-Request / MD5 challenge)
RADIUS Access-Request
(EAP-Response / MD5 challenge)
RADIUS Access-Accept
(EAP-Success)
Port authorized
Handshake timer
Port unauthorized
1-7
Server
EAPOR

Hide quick links:

Advertisement

Chapters

Table of Contents
loading

This manual is also suitable for:

S7910eS7906e-vS7903eS7903e-sS7902e

Table of Contents