3Com Switch 4800G 24-Port Configuration Manual page 723

Switch 4800g family 24-port, pwr 24-port, 48-port, pwr 48-port, 24-port sfp
Hide thumbs Also See for Switch 4800G 24-Port:
Table of Contents

Advertisement

Figure 218 Message exchange in EAP termination mode
Supplicant system
Different from the authentication process in EAP relay mode, it is the authenticator
that generates the random challenge for encrypting the user password
information in EAP termination authentication process. Consequently, the
authenticator sends the challenge together with the username and encrypted
password information from the supplicant to the RADIUS server for
authentication.
802.1x Timers
Several timers are used in the 802.1x authentication process to guarantee that the
supplicants, the authenticators, and the RADIUS server interact with each other in
a reasonable manner. The following are the major 802.1x timers:
Username request timeout timer (tx-period): This timer is used in two cases,
one is when an authenticator retransmits an EAP-Request/Identity frame and
the other is when an authenticator multicasts an EAP-Request/Identity frame.
Once an authenticator sends an EAP-Request/Identity frame to a supplicant, it
starts this timer. If this timer expires but it receives no response from the
supplicant, it retransmits the request. To cooperate with a supplicant system
that does not send EAPOL-Start requests unsolicitedly, the authenticator
EAPOL
PAE
EAPOL-Start
EAP- Resquest / Identity
EAP - Response / Identity
EAP - Request / MD5 challenge
EAP - Response / MD5 challenge
EAP- Success
Handshake request
[ EAP - Request / Identity ]
Handshake response
[ EAP - Response / Identity ]
......
EAPOL- Logoff
Authenticator system
PAE
RADIUS Access - Request
(CHAP- Response / MD5 challenge)
RADIUS Access - Accept
(CHAP- Success )
Port authorized
Handshake timer
Port unauthorized
802.1x Overview
723
RADIUS
RADUIS
server

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents