3Com MSR 50 Series Configuration Manual page 1730

3com msr 30-16: software guide
Hide thumbs Also See for MSR 50 Series:
Table of Contents

Advertisement

1730
C
92: 802.1
HAPTER
X
C
ONFIGURATION
Figure 498 Architecture of 802.1x
Supplicant system
Supplicant PAE
Supplicant system: A system at one end of the LAN segment, which is
authenticated by the authenticator system at the other end. A supplicant
system is usually a user-end device and initiates 802.1x authentication through
802.1x client software supporting the EAP over LANs (EAPOL) protocol.
Authenticator system: A system at the other end of the LAN segment, which
authenticates the connected supplicant system. An authenticator system is
usually an 802.1x-enabled network device and provides ports (physical or
logical) for supplicants to access the LAN.
Authentication server system: The system providing authentication,
authorization, and accounting services for the authenticator system. The
authentication server, usually a Remote Authentication Dial-in User Service
(RADIUS) server, maintains user information like username, password, VLAN
that the user belongs to, committed access rate (CAR) parameters, priority, and
ACLs.
The above systems involve three basic concepts: PAE, Controlled port, Control
direction.
PAE
Port access entity (PAE) refers to the entity that performs the 802.1x algorithm and
protocol operations.
The authenticator PAE uses the authentication server to authenticate a
supplicant trying to access the LAN and controls the status of the controlled
port according to the authentication result, putting the controlled port in the
state of authorized or unauthorized. In authorized state, the controlled port
permits all packets of the supplicant and the supplicant can access network
resources normally. In unauthorized state, the controlled port permits only
EAPOL frames and the supplicant cannot access network resources.
The supplicant PAE responds to the authentication request of the authenticator
PAE and provides authentication information. The supplicant PAE can also send
authentication requests and logoff requests to the authenticator.
Controlled port and uncontrolled port
An authenticator provides ports for supplicants to access the LAN. Each of the
ports can be regarded as two logical ports: a controlled port and an uncontrolled
port.
Authenticator system
Authenticator
Services offered by
Authenticator s
system
Port
unauthorized
LAN/WLAN
PAE
EAP protocol
exchanges
carried in
higher layer
protocol
Authentication
server system
Authentication
server

Hide quick links:

Advertisement

Table of Contents

Troubleshooting

loading

Table of Contents