Portal Authentication Process - HPE FlexNetwork 10500 Series Security Configuration Manual

Hide thumbs Also See for FlexNetwork 10500 Series:
Table of Contents

Advertisement

Figure 53 Portal support for EAP working flow diagram
Authentication
client
As shown in
authentication packets. The portal authentication server and the access device exchange portal
authentication packets that carry the EAP-Message attributes. The access device and the RADIUS
server exchange RADIUS packets that carry the EAP-Message attributes. The RADIUS server that
supports the EAP server function processes the EAP packets encapsulated in the EAP-Message
attributes, and provides the EAP authentication result.
The access device does not process but only transports EAP-Message attributes between the portal
authentication server and the RADIUS server. Therefore, the access device requires no additional
configuration to support EAP authentication.
NOTE:
To use portal authentication that supports EAP, the portal authentication server and client must be the HPE
IMC portal server and the HPE iNode portal client.
Local portal authentication does not support EAP authentication.

Portal authentication process

Direct authentication and cross-subnet authentication share the same authentication process.
Re-DHCP authentication has a different process as it has two address allocation procedures.
Direct authentication/cross-subnet authentication process (with CHAP/PAP authentication)
Figure 54 Direct authentication/cross-subnet authentication process
Authentication
client
1) Initiate a connection
The direct/cross-subnet authentication process is as follows:
1.
A portal user access the Internet through HTTP, and the HTTP packet arrives at the access
device.
If the packet matches a portal free rule, the access device allows the packet to pass.
If the packet does not match any portal-free rule, the access device redirects the packet to
the portal Web server. The portal Web server pushes the Web authentication page to the
user for him to enter his username and password.
EAP
Portal server
Figure
53, the authentication client and the portal authentication server exchange EAP
Portal Web
authentication
server
2) User information
7) Notify login
success
Access
Portal
device
(EAP-Message)
Portal
Access
device
server
3) CHAP authentication
4) Authentication request
Timer
6) Authentication reply
8) Authentication reply
acknowledgment
9) Security check
10) Authorization
171
RADIUS
RADIUS server
(EAP-Message)
AAA server
5) RADIUS
authentication
(EAP server)
Security
policy server

Advertisement

Table of Contents
loading

Table of Contents