Eapol-Based Security - Nortel business policy switch 2000 User Manual

Table of Contents

Advertisement

80 Chapter 1 The Business Policy Switch 2000

EAPOL-based security

BPS 2000 software version 1.1 provides support for security based on the
Extensible Authentication Protocol over LAN (EAPOL), which uses the EAP as
described in the IEEE Draft P802.1X to allow you to set up network access
control on internal LANs.
For information on configuring EAPOL-based security using the Console
Interface (CI) menus, refer to Chapter 3. To configure this feature using the
Web-based management system, refer to Using Web-based Management for the
Business Policy Switch 2000 Software Version 2.0. To use Device Manager (DM)
to configure EAPOL-based security, refer to Reference for the Business Policy
Switch 2000 Management Software Version 2.0. And, to configure this feature
using CLI commands, refer to Reference for the Business Policy Switch 2000
Command Line Interface Software Version 2.0. book.
EAP allows the exchange of authentication information between any end station
or server connected to the switch and an authentication server (such as a RADIUS
server). The EAPOL-based security feature operates in conjunction with a
RADIUS-based server to extend the benefits of remote authentication to internal
LAN clients.
The following example illustrates how the BPS 2000, configured with the
EAPOL-based security feature, reacts to a new network connection:
The switch detects a new connection on one of its ports.
— The switch requests a user ID from the new client.
— EAPOL encapsulates the user ID and forwards it to the RADIUS server.
— The RADIUS server responds with a request for the user's password.
The new client forwards an encrypted password to the switch, within the
EAPOL packet.
— The switch relays the EAPOL packet to the RADIUS server.
— If the RADIUS server validates the password, the new client is allowed
Some components and terms used with EAPOL-based security are:
Supplicant—the device applying for access to the network.
208700-C
access to the switch and the network.

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents