Controlled And Uncontrolled Ports - Dell PowerConnect B-RX Configuration Manual

Bigiron rx series configuration guide v02.7.02
Hide thumbs Also See for PowerConnect B-RX:
Table of Contents

Advertisement

33
How 802.1x port security works

Controlled and uncontrolled ports

A physical port on the device used with 802.1x port security has two virtual access points, a
controlled port and an uncontrolled port. The controlled port provides full access to the network.
The uncontrolled port provides access only for EAPOL traffic between the Client and the
Authentication Server. When a Client is successfully authenticated, the controlled port is opened to
the Client.
FIGURE 122
BigIron Device
(Authenticator)
Before a Client is authenticated, only the uncontrolled port on the Authenticator is open. The
uncontrolled port allows only EAPOL frames to be exchanged between the Client and the
Authentication Server. The controlled port is in the unauthorized state and allows no traffic to pass
through.
During authentication, EAPOL messages are exchanged between the Supplicant PAE and the
Authenticator PAE, and RADIUS messages are exchanged between the Authenticator PAE and the
Authentication Server. Refer to
example of this process. If the Client is successfully authenticated, the controlled port becomes
authorized, and traffic from the Client can flow through the port normally.
By default, all controlled ports on the device are placed in the authorized state, allowing all traffic.
When authentication is activated on an 802.1x-enabled interface, the interface's controlled port is
placed initially in the unauthorized state. When a Client connected to the port is successfully
authenticated, the controlled port is then placed in the authorized state until the Client logs off.
Refer to
956
Figure 122
illustrates this concept.
Controlled and uncontrolled ports before and after client authentication
Authentication
Server
Services
PAE
Uncontrolled Port
Physical Port
PAE
802.1X-Enabled
Supplicant
Before Authentication
"Message exchange during authentication"
"Enabling 802.1x port security"
Controlled Port
Uncontrolled Port
(Unauthorized)
on page 966 for more information.
Authentication
Server
Services
PAE
BigIron Device
(Authenticator)
Controlled Port
(Authorized)
Physical Port
PAE
802.1X-Enabled
Supplicant
After Authentication
on page 957 for an
BigIron RX Series Configuration Guide
53-1001810-01

Advertisement

Table of Contents
loading

This manual is also suitable for:

Brocade dcx-4sBrocade dcx

Table of Contents