02.10.2013 Views

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

FTOS Configuration Guide for the C-Series - Force10 Networks

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

4. The au<strong>the</strong>ntication server replies with an Access-Challenge. The Access-Challenge is request that <strong>the</strong><br />

supplicant prove that it is who it claims to be, using a specified method (an EAP-Method). The<br />

challenge is translated and <strong>for</strong>warded to <strong>the</strong> supplicant by <strong>the</strong> au<strong>the</strong>nticator.<br />

5. The supplicant can negotiate <strong>the</strong> au<strong>the</strong>ntication method, but if it is acceptable, <strong>the</strong> supplicant provides<br />

<strong>the</strong> requested challenge in<strong>for</strong>mation in an EAP Response, which is translated and <strong>for</strong>warded to <strong>the</strong><br />

au<strong>the</strong>ntication server as ano<strong>the</strong>r Access-Request.<br />

6. If <strong>the</strong> identity in<strong>for</strong>mation provided by <strong>the</strong> supplicant is valid, <strong>the</strong> au<strong>the</strong>ntication server sends an<br />

Access-Accept frame in which network privileges are specified. The au<strong>the</strong>nticator changes <strong>the</strong> port<br />

state to authorized, and <strong>for</strong>wards an EAP Success frame. If <strong>the</strong> identity in<strong>for</strong>mation is invalid, <strong>the</strong><br />

server sends and Access-Reject frame. The port state remains unauthorized, and <strong>the</strong> au<strong>the</strong>nticator<br />

<strong>for</strong>wards EAP Failure frame.<br />

Figure 475 802.1X Au<strong>the</strong>ntication Process<br />

Supplicant Au<strong>the</strong>nticator Au<strong>the</strong>ntication<br />

Server<br />

EAP over LAN (EAPOL) EAP over RADIUS<br />

Request Identity<br />

Response Identity<br />

EAP Request<br />

EAP Reponse<br />

EAP {Sucess | Failure}<br />

Access Request<br />

Access Challenge<br />

Access Request<br />

Access {Accept | Reject}<br />

676 802.1X

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!