Authentication Procedure - Huawei Quidway S3100 Series Operation Manual

Table of Contents

Advertisement

Operation Manual – 802.1x
Quidway S3100 Series Ethernet Switches
1.1.4 802.1x Authentication Procedure
A Quidway S3100 series switch can authenticate supplicant systems in EAP
terminating mode or EAP relay mode.
I. EAP relay mode
This mode is defined in 802.1x. In this mode, EAP-packets are encapsulated in higher
level protocol (such as EAPoR) packets to allow them successfully reach the
authentication server. This mode normally requires the RADIUS server to support the
two newly-added fields: the EAP-message field (with a value of 79) and the
Message-authenticator field (with a value of 80).
Three authentication ways, EAP-MD5, EAP-TLS (transport layer security), and PEAP
(protected extensible authentication protocol), are available for the EAP relay mode.
EAP-MD5 authenticates the supplicant system. The RADIUS server sends MD5
keys (contained in EAP-request/MD5 challenge packets) to the supplicant system,
which in turn encrypts the passwords using the MD5 keys.
EAP-TLS authenticates both the supplicant system and the RADIUS server by
checking their security licenses to prevent data from being stolen.
PEAP creates and uses TLS security channels to ensure data integrity and then
performs new EAP negotiations to verify supplicant systems.
Figure 1-8 describes the basic EAP-MD5 authentication procedure.
Huawei Technologies Proprietary
1-6
Chapter 1 802.1x Configuration

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents