25.02.2013 Views

TCP/IP Tutorial and Technical Overview - IBM Redbooks

TCP/IP Tutorial and Technical Overview - IBM Redbooks

TCP/IP Tutorial and Technical Overview - IBM Redbooks

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Figure 23-21 shows the sniffer trace for an EAPoL-Logoff packet.<br />

Figure 23-21 EAPoL-Logoff packet<br />

Figure 23-22 shows the EAPOL-Key packet format. The Packet type field in the<br />

802.1x header has the value of 3 to indicate that it is an EAPOL-Key packet.<br />

6 6 2 1 1 2 1 2 8 16 1 16<br />

(Bytes)<br />

N(Bytes)<br />

Destination<br />

address<br />

Source<br />

address<br />

Ethernet Header<br />

Type<br />

0x888E<br />

Protocol<br />

version<br />

1<br />

Figure 23-22 EAPoL-Key packet format<br />

Figure 23-23 shows the sniffer trace for an EAPoL-Key packet.<br />

Figure 23-23 EAPoL-Key packet<br />

23.3.1 Port based network access control functional considerations<br />

The st<strong>and</strong>ard for port based network access control allows for the flexibility in<br />

deployment. Any device capable of supporting 802.1x can act as any<br />

combination of a supplicant, authenticator, <strong>and</strong> authentication server. However,<br />

to leverage the greatest amount of functionality, the IEEE 802.1x st<strong>and</strong>ard<br />

suggests the use of the following aspects.<br />

904 <strong>TCP</strong>/<strong>IP</strong> <strong>Tutorial</strong> <strong>and</strong> <strong>Technical</strong> <strong>Overview</strong><br />

Packet<br />

type<br />

3<br />

802.1x/EAPOL Header<br />

Packet<br />

body length Descriptor<br />

type<br />

key<br />

lengt<br />

h<br />

Replay<br />

counter<br />

Key<br />

IV<br />

Key descriptor<br />

Key<br />

index<br />

Key<br />

signature<br />

Key

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!