Cisco 3750G - Catalyst Integrated Wireless LAN Controller Configuration Manual page 260

Software configuration guide
Hide thumbs Also See for 3750G - Catalyst Integrated Wireless LAN Controller:
Table of Contents

Advertisement

Understanding IEEE 802.1x Port-Based Authentication
The specific exchange of EAP frames depends on the authentication method being used.
shows a message exchange initiated by the client when the client uses the One-Time-Password (OTP)
authentication method with a RADIUS server.
Figure 10-3
Client
If IEEE 802.1x authentication times out while waiting for an EAPOL message exchange and MAC
authentication bypass is enabled, the switch can authorize the client when the switch detects an Ethernet
packet from the client. The switch uses the MAC address of the client as its identity and includes this
information in the RADIUS-access/request frame that is sent to the RADIUS server. After the server
sends the switch the RADIUS-access/accept frame (authorization is successful), the port becomes
authorized. If authorization fails and a guest VLAN is specified, the switch assigns the port to the guest
VLAN. If the switch detects an EAPOL packet while waiting for an Ethernet packet, the switch stops
the MAC authentication bypass process and stops IEEE 802.1x authentication.
Figure 10-4
Catalyst 3750 Switch Software Configuration Guide
10-6
Message Exchange
EAPOL-Start
EAP-Request/Identity
EAP-Response/Identity
EAP-Request/OTP
EAP-Response/OTP
EAP-Success
Port Authorized
EAPOL-Logoff
Port Unauthorized
shows the message exchange during MAC authentication bypass.
Chapter 10
Configuring IEEE 802.1x Port-Based Authentication
Authentication
(RADIUS)
RADIUS Access-Request
RADIUS Access-Challenge
RADIUS Access-Request
RADIUS Access-Accept
Figure 10-3
server
OL-8550-02

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the 3750G - Catalyst Integrated Wireless LAN Controller and is the answer not in the manual?

Table of Contents