3Com 4500 PWR 26-Port Configuration Manual page 350

Hide thumbs Also See for 4500 PWR 26-Port:
Table of Contents

Advertisement

E
AP elay mode
r
This mo
de is defined in 802.1x. In this mode, EAP packets are encapsulated in higher level protocol
(such as EAPoR) packets to enable them to successfully reach the authentication server. Normally, this
mode requires that the RADIUS server support the two newly-added fields: the EAP-message field
(with a valu
e of 79) and the Message-authenticator field (with a value of 80).
Four authentication ways, namely EAP-MD5, EAP-TLS (transport layer security), EAP-TTLS (tunneled
tran
sport layer security), and Protected Extensi
EAP relay mode.
EAP-MD5 authenticates the supplicant system. The RADIUS server sends MD5 keys (contained in
EAP-request/MD5 challenge packets) to the supplicant syste
passwords using the MD5 keys.
EAP-TLS allows the supplicant system and the RADIUS server to check each other'
certificate and authenticate each other's identity, guaranteeing that data is t
destination and preventing data from being intercepted.
EAP-TTLS is a kind of extended EAP-TLS. EAP-TLS
between the client and authentication server. EAP-TTLS transm
established using TLS.
PEAP creates and uses TLS security channels to ensure data integrity and then
negotiations to verify supplicant systems.
Figure 28-8
describes the basic EAP-MD5 authentication procedure.
Figure 28-8 802.1x authentication procedure (in EAP relay mode)
EAPOL
Supplicant system
PAE
EAPOL - Start
EAP- Request / Identity
EAP- Response / Identity
EAP- Request / MD5 challenge
EAP- Response / MD5 challenge
EAP-Success
Handshake request
[ EAP- Request / Identity ]
Handshake response
[ EAP- Response / Identity ]
EAPOL -Logoff
ble Authentication Protocol (PEAP), are available in the
Authenticator system
PAE
RADIUS Access - Request
(EAP- Response / Identity)
RADIUS Access -Challenge
( EAP- Request / MD5 challenge)
( EAP- Response / MD5 challenge)
Port authorized
Handshake timer
......
Port unauthorized
28-6
m, which in turn encrypts the
implements bidirectional authentication
EAPOR
RADUIS
server
RADIUS Access - Request
RADIUS Access -Accept
(EAP-Success)
s security
ransferred to the right
it message using a tunnel
performs new EAP

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

4500 26-port4500 50-port

Table of Contents