Timer - Huawei Quidway S3100 Series Operation Manual

Table of Contents

Advertisement

Operation Manual – 802.1x
Quidway S3100 Series Ethernet Switches
Supplicant
Supplicant
Supplicant
syst em
syst em
syst em
Figure 1-9 802.1x authentication procedure (in EAP terminating mode)
The authentication procedure in EAP terminating mode is the same as that in the EAP
relay mode except that the randomly-generated key in the EAP terminating mode is
generated by the switch, and that it is the switch that sends the user name, the
randomly-generated key, and the supplicant system-encrypted password to the
RADIUS server for further authentication.
1.1.5 802.1x Timer
In 802.1 x authentication, the following timers are used to ensure that the supplicant
system, the switch, and the RADIUS server interact in an orderly way:
Transmission timer: This timer sets the tx-period and is triggered by the switch
when the switch sends a request/identity packet to a supplicant system. The
switch sends another request/identity packet to the supplicant system if the
EAPOL
EAPOL
EAPOL
EAPOL-Start
EAPOL-Start
EAPOL-Start
EAP-Request/Identity
EAP-Request/Identity
EAP-Request/Identity
EAP-Response/Identity
EAP-Response/Identity
EAP-Response/Identity
EAP-Request/MD5 Challenge
EAP-Request/MD5 Challenge
EAP-Request/MD5 Challenge
EAP-Response/MD5 Challenge
EAP-Response/MD5 Challenge
EAP-Response/MD5 Challenge
EAP-Success
EAP-Success
EAP-Success
Hands hake request pac ket
Hands hake request pac ket
Hands hake request pac ket
[EAP-Request/Identity]
[EAP-Request/Identity]
[EAP-Request/Identity]
Hands hake reply pac ket
Hands hake reply pac ket
Hands hake reply pac ket
[EAP-Response/Identity]
[EAP-Response/Identity]
[EAP-Response/Identity]
......
......
......
EAPOL-Logoff
EAPOL-Logoff
EAPOL-Logoff
Huawei Technologies Proprietary
RADIUS
RADIUS
RADIUS
Switc h
Switc h
Switc h
RADIUS Access-Reque
RADIUS Access-Reque
RADIUS Access-Reque
(CHAP-Response/MD5 Chal
(CHAP-Response/MD5 Chal
(CHAP-Response/MD5 Chal
RADIUS Access-Acce
RADIUS Access-Acce
RADIUS Access-Acce
(CHAP-Success)
(CHAP-Success)
(CHAP-Success)
Port acc epted
Port acc epted
Port acc epted
Hands hake ti mer ti me out
Hands hake ti mer ti me out
Hands hake ti mer ti me out
Port rejected
Port rejected
Port rejected
1-9
Chapter 1 802.1x Configuration
RADIUS ser ver
RADIUS ser ver
RADIUS ser ver
st
st
st
lenge)
lenge)
lenge)
pt
pt
pt

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents