Planet IGS-801 [95/120] X network access control

User’s Manual of IGS-801M
4.9 802.1X N
Overview of 802.1X (Por
In the is called the supplicant, the switch is the authenticator, and the RADIUS server is the
authenticati . The switch ac
supplicant and the authentication server ween the supplicant and the switch are special 802.1X frames,
known as EAPOL (EAP Over LANs) frames. EAPOL frames encapsulate EAP PDUs (RFC3748). Frames sent between
the switch and the RADIUS serv ther with
other attributes like the switch's t number on the switch. EAP is very flexible, in
that it allows for different Challenge, PEAP, and TLS. The important thing is that the
authenticator (the switch) d ication method the supplicant and the authentication server
are using, or how many eded for a particular method. The switch simply encapsulates
the EAP part of the fram RADIUS) and forwards it.
hen authentication is complete, the RADIUS server sends a special packet containing a success or failure indication.
Besides forwarding this decision to the supplicant, the switch uses it to open up or block traffic on the switch port
connected to the supplicant.
etwork Access Control
t-Based) Authentication
802.1X-world, the user
on server ts as the man-in-the-middle, forwarding requests and responses between the
. Frames sent bet
er are RADIUS packets. RADIUS packets also encapsulate EAP PDUs toge
IP address, name, and the supplicant's por
authentication methods, like MD5-
oesn't need to know which authent
information exchange frames are ne
e into the relevant type (EAPOL or
W
95

Содержание

Скачать