Mode Of Operation - Nokia ESB26 User Manual

Gigabit ethernet switch
Table of Contents

Advertisement

34.
802.1X Port-Based Authentication

Mode of Operation

When a BiNOS switch is configured as an authenticator, the ports of the switch must be
configured for authorization.
When the authenticator detects that the link with the supplicant is active and an EAPOL start-
packet is received, the authenticator port sends an EAP packet to the supplicant requesting the
supplicant's identification. If the supplicant attached to the switch does not understand the
EAP packet that is received from the switch, it does not send an ID and the port remains
unauthorized. In this state, the port does not pass any user traffic. If the supplicant is running
the 802.1X EAP, it responds to the request with its configured ID.
When the authenticator receives the ID from the supplicant, it passes the ID information to an
authentication server (RADIUS server).
The authentication server sends back a challenge to the authenticator. The authenticator
repackages it into EAPOL, and sends it to the supplicant.
The supplicant responds to the challenge via the authenticator and passes the response to the
authentication server.
If the supplicant provides a proper ID, the authentication server responds with a success
message, which is then passed onto the supplicant. If the response is a failure, the port
remains unauthorized and no user traffic is allowed to pass through It. The port also remains
unauthorized and does not pass any traffic, if there is no response from the RADIUS server. It
is possible to configure the switch to use multiple radius servers in the event that the server is
unreachable.
Figure 34-1 displays the process of authorization.
Figure 34-1 Authentication Process
The authenticator and the supplicant communicate with each other through Layer2 EAPOL
packets, while the authenticator and RADIUS server communicate through IP/UDP RADIUS
packets. The authenticator performs EAPOL
IP/UDP RADIUS packets capsulation.
Supplicant Modes
802.1X supports three supplicant modes: Single Host, Multiple Hosts and Multiple Hosts/Per
MAC mode. The table below shows the 802.1X supplicant modes.
MN700004 Rev 01
361

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents