SignaMax 065-7840 User's Guide Page 118

  • Download
  • Add to my manuals
  • Print
  • Page
    / 228
  • Table of contents
  • BOOKMARKS
  • Rated. / 5. Based on customer reviews
Page view 117
Signamax 065-7840 24-Port 10/100/1000BaseT/TX Managed Switch
108
The overview of operation flow shown in Fig. 3-49 is quite simple. When
the Supplicant PAE issues a request to the Authenticator PAE, the
Authenticator and Supplicant exchange an authentication message.
Then, the Authenticator passes the request to the RADIUS server for
verification. Finally, the RADIUS server replies if the request is granted or
denied.
While in the authentication process, the message packets, encapsulated
by Extensible Authentication Protocol over LAN (EAPOL), are exchanged
between an authenticator PAE and a supplicant PAE. The Authenticator
exchanges the message to authentication server using EAP
encapsulation. Before successfully authenticating, the supplicant can
only contact the authenticator to perform authentication message
exchange or access the network from the uncontrolled port.
Fig. 3-49
Fig. 3-50 shows a typical configuration: a single supplicant, an authenticator
and an authentication server. B and C are on the internal network, D is the
Authentication server running RADIUS, the switch at the central location acts as the
Authenticator connecting to PC A ,and A is a PC outside the controlled port, running
Supplicant PAE. In this case, if PC A wants to access the services on devices B and
C, it must first exchange the authentication message with the authenticator on the
port on which it is connected via an EAPOL packet. The authenticator transfers the
supplicant’s credentials to the Authentication server for verification. If successful,
the authentication server will notify the authenticator that access is granted. PC A is
then allowed to access B and C via the switch. If there are two switches directly
connected together instead of a single one, for the link connecting two switches, it
may have to act in two port roles at the end of the link: authenticator and supplicant,
because the traffic is bi-directional.
LAN
Authenticator
PAE
Services Offered
by Authenticator
(e.g. Bridge
Relay)
Authenticator’s System
Authentication
Server’s System
Authentication
Server
Supplicant
PAE
Supplicant’s
System
Uncontrolled port Controlled port
MAC Enable
Port Authorize
Page view 117
1 2 ... 113 114 115 116 117 118 119 120 121 122 123 ... 227 228

Comments to this Manuals

No comments