Timer - H3C S7500 Series Operation Manual

Hide thumbs Also See for S7500 Series:
Table of Contents

Advertisement

Operation Manual – 802.1x
H3C S7500 Series Ethernet Switches
Supplicant
Supplicant
PAE
PAE
EAP-Response/MD5 Challenge
EAP-Response/MD5 Challenge
Figure 1-9 802.1x authentication procedure (in EAP termination mode)
The authentication procedure in EAP termination mode is the same as that in the EAP
relay mode except that the randomly-generated key in the EAP termination mode is
generated by the switch, and that it is the switch that sends the user name, the
randomly-generated key, and the supplicant system-encrypted password to the
RADIUS server for further authentication.
1.1.5 802.1x Timer
In 802.1 x authentication, the following timers are used to ensure that the supplicant
system, the switch, and the RADIUS server interact orderly:
Transmission timer (tx-period): This timer sets the transmission period and is
triggered by the switch in one of the following two cases: The first case is when a
supplicant system requests for authentication. The switch sends a unicast
request/identity packet to the supplicant system and then enables the
transmission timer. The switch will send another request/identity packet to the
supplicant system if it has not received any response from the supplicant system
when this timer times out. The second case is when the switch authenticates the
802.1x client who does not request for authentication actively. The switch sends
EAPOL
EAPOL
EAPOL-Start
EAPOL-Start
EAP-Request/Identity
EAP-Request/Identity
EAP-Response/Identity
EAP-Response/Identity
EAP-Request/MD5 Challenge
EAP-Request/MD5 Challenge
EAP-Success
EAP-Success
authorized
authorized
Handshake request
Handshake request
[EAP-Request/Identity]
[EAP-Request/Identity]
Handshake response
Handshake response
[EAP-Response/Identity]
[EAP-Response/Identity]
......
......
EAPOL-Logoff
EAPOL-Logoff
unauthorized
unauthorized
RADIUS
RADIUS
Sw itch
Sw itch
RADIUS Access-R
RADIUS Access-R
(CHA P-Response/MD5 C
(CHA P-Response/MD5 C
RADIUS Access-A
RADIUS Access-A
(CHA P-Succes
(CHA P-Succes
Port
Port
Handshake timer
Handshake timer
times out
times out
Port
Port
1-9
Chapter 1 802.1x Configuration
RADIUS server
RADIUS server
equest
equest
hallenge)
hallenge)
ccept
ccept
s)
s)

Advertisement

Table of Contents
loading

Table of Contents