Authentication Procedure - H3C S7500 Series Operation Manual

Hide thumbs Also See for S7500 Series:
Table of Contents

Advertisement

Operation Manual – 802.1x
H3C S7500 Series Ethernet Switches
0
0
Type
Type
Figure 1-6 Encapsulation format of the EAP-message attribute
The Message-authenticator attribute, as shown in
requesting packets from being snooped during authentications using CHAP, EAP, and
so on. A packet with the EAP-message attribute must also have the
Message-authenticator attribute; otherwise the packet is regarded as invalid and will be
discarded.
0
type=80
Figure 1-7 Encapsulation format of the Message-authenticator attribut
1.1.4 802.1x Authentication Procedure
An H3C S7500 series switch can authenticate supplicant systems in EAP termination
mode or EAP relay mode.
I. EAP relay mode
This mode is defined in 802.1x. In this mode, EAP protocol is carried over other upper
layer protocols like EAP over RADIUS so that EAP packets can traverse through
complicated networks and arrive the authentication server. This mode normally
requires the RADIUS server to support the two newly added attributes: EAP-message
(a value of 79) and Message-authenticator (a value of 80).
For EAP relay mode, three authentication ways are supported: EAP-MD5, transport
layer security (EAP-TLS ), and protected extensible authentication protocol (PEAP).
The following presents a description of these three authentication ways:
EAP-MD5 authenticates the supplicant system. The RADIUS server sends MD5
keys (contained in EAP-request/MD5 challenge packets) to the supplicant system,
which in turn encrypts passwords using the MD5 keys.
EAP-TLS authenticates both the supplicant system and the RADIUS server. With
MAP-TLS authentication, the supplicant system and the RADIUS server checks
the security certificate of each other to prevent data from being stolen.
PEAP creates and uses TLS security channels to ensure data integrity and then
performs new EAP negotiation to verify the supplicant system.
Figure 1-8
1
1
2
2
Length
Length
1
2
length=18
takes EAP-MD5 as an example to introduce basic authentication procedure.
String
String
EAP packet
EAP packet
Figure
1-7, is used to prevent access
string...
1-6
Chapter 1 802.1x Configuration
17
e

Advertisement

Table of Contents
loading

Table of Contents