Message Exchange During Authentication - Dell PowerConnect B-FCXs Configuration Manual

Powerconnect b-series fcx
Hide thumbs Also See for PowerConnect B-FCXs:
Table of Contents

Advertisement

34
How 802.1X port security works
FIGURE 155
(Authenticator)
Before a Client is authenticated, only the uncontrolled port on the Authenticator is open. The
uncontrolled port allows only EAPOL frames to be exchanged between the Client and the
Authentication Server. The controlled port is in the unauthorized state and allows no traffic to pass
through.
During authentication, EAPOL messages are exchanged between the Supplicant PAE and the
Authenticator PAE, and RADIUS messages are exchanged between the Authenticator PAE and the
Authentication Server.Refer to
example of this process. If the Client is successfully authenticated, the controlled port becomes
authorized, and traffic from the Client can flow through the port normally.
By default, all controlled ports on the PowerConnect device are placed in the authorized state,
allowing all traffic. When authentication is activated on an 802.1X-enabled interface, the interface
controlled port is placed initially in the unauthorized state. When a Client connected to the port is
successfully authenticated, the controlled port is then placed in the authorized state until the
Client logs off.Refer to

Message exchange during authentication

Figure 156
PowerConnect switch acting as Authenticator, and a RADIUS server acting as an Authentication
Server.
1220
Controlled and uncontrolled ports before and after client authentication
Authentication
Server
Services
PAE
Switch
Uncontrolled Port
Physical Port
PAE
802.1X-Enabled
Supplicant
Before Authentication
"Enabling 802.1X port security"
illustrates a sample exchange of messages between an 802.1X-enabled Client, a
Controlled Port
Uncontrolled Port
(Unauthorized)
"Message exchange during authentication"
on page 1237 for more information.
Authentication
Server
Services
PAE
Controlled Port
(Authorized)
Physical Port
PAE
802.1X-Enabled
Supplicant
After Authentication
on page 1220 for an
PowerConnect B-Series FCX Configuration Guide
Switch
(Authenticator)
53-1002266-01

Advertisement

Table of Contents
loading

Table of Contents