HP 3600 v2 Series Security Configuration Manual page 143

Hide thumbs Also See for 3600 v2 Series:
Table of Contents

Advertisement

Portal support for EAP authentication process
Figure 58 Portal support for EAP authentication process
All portal authentication modes share the same EAP authentication steps. The following takes the direct
portal authentication as an example to show the EAP authentication process:
The authentication client sends an EAP Request/Identity message to the portal server to initiate an
1.
EAP authentication process.
The portal server sends a portal authentication request to the access device, and starts a timer to
2.
wait for the portal authentication reply. The portal authentication request contains several
EAP-Message attributes, which are used to encapsulate the EAP packet sent from the
authentication client and carry the certificate information of the client.
After the access device receives the portal authentication request, it constructs a RADIUS
3.
authentication request and sends it to the RADIUS server. The EAP-Message attributes in the
RADIUS authentication request are those carried in the received portal authentication request.
The access device sends a certificate request to the portal server according to the reply received
4.
from the RADIUS server. The certificate request also contains several EAP-Message attributes,
which are used to transfer the certificate information of the RADIUS server. The EAP-Message
attributes in the certificate request are those carried in the RADIUS authentication reply.
After receiving the certificate request, the portal server sends an EAP authentication reply to the
5.
authentication client, carrying the EAP-Message attribute values.
The authentication client sends another EAP request to continue the EAP authentication with the
6.
RADIUS server, during which there may be several portal authentication requests. The subsequent
authentication processes are the same as that initiated by the first EAP request, except that the EAP
request types vary with the EAP authentication phases.
After the authentication client passes the EAP authentication, the RADIUS server sends an
7.
authentication reply to the access device. This reply carries the EAP-Success message in the
EAP-Message attribute.
132

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

A3100-48 v2

Table of Contents