Authentication Server - Cisco WS-C2950SX-48-SI Configuration Manual

Catalyst 4500 series switches
Hide thumbs Also See for WS-C2950SX-48-SI:
Table of Contents

Advertisement

Chapter 31
Configuring 802.1x Authentication
Table 31-1 802.1x Terminology
Term
Authenticator PAE

Authentication server

Authorized state
Both
Controlled port
EAP
EAPOL
In
Port
PAE
PDU
RADIUS
PAE
Unauthorized state
Uncontrolled port
1. EAPOL = Extensible Authorization Protocol over LAN
2. PAE = Port access entity
Authentication Server
The frames exchanged between the authenticator and the authentication server are dependent on the
authentication mechanism, so they are not defined by the 802.1x standard. You can use other protocols,
but we recommend RADIUS for authentication, particularly when the authentication server is located
remotely, because RADIUS has extensions that support encapsulation of EAP frames built into it.
78-15486-01
Definition
(Referred to as the "authenticator") entity at one end of a point-to-point LAN
segment that enforces host authentication. The authenticator is independent
of the actual authentication method and functions only as a pass-through for
the authentication exchange. It communicates with the host, submits the
information from the host to the authentication server, and authorizes the host
when instructed to do so by the authentication server.
Entity that provides the authentication service for the authenticator PAE. It
checks the credentials of the host PAE, and then notifies its client, the
authenticator PAE, whether the host PAE is authorized to access the
LAN/switch services.
Status of the port after the host PAE is authorized.
Bidirectional flow control, incoming and outgoing, at an unauthorized switch
port.
Secured access point.
Extensible Authentication Protocol.
1
Encapsulated EAP messages that can be handled directly by a LAN MAC
service.
Flow control only on incoming frames in an unauthorized switch port.
Single point of attachment to the LAN infrastructure (for example, MAC
bridge ports).
2
Protocol object that is associated with a specific system port.
Protocol data unit.
Remote Access Dial In User Service.
(Referred to as the "host") entity that requests access to the LAN/switch
services and responds to information requests from the authenticator.
Status of the port before the host PAE is authorized.
Unsecured access point that allows the uncontrolled exchange of PDUs.
Catalyst 4500 Series, Catalyst 2948G, Catalyst 2980G Switches Software Configuration Guide
Understanding How 802.1x Authentication Works
Release 8.1
31-5

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents