ZyXEL Communications 320W manual Eapol Exchange between 802.1x Authenticator and Supplicant

Page 41

P320W Support Notes

The EAP protocol can support multiple authentication mechanisms, such as MD5-challenge, One-Time Passwords, Generic Token Card, TLS and TTLS etc. Typically, the authenticator will send an initial Identity Request followed by one or more Requests for authentication information. When supplicant receive the EAP request, it will reply associated EAP response. So far, ZyXEL Wireless AP only supports MD-5 challenge authentication mechanism, but will support TLS and TTLS in the future.

EAPOL Exchange between 802.1x Authenticator and Supplicant

The authenticator or the supplicant can initiate authentication. If you enable 802.1x authentication on the Wireless AP, the authenticator must initiate authentication when it determines that the Wireless link state transitions from down to up. It then sends an EAP-request/identity frame to the 802.1x client to request its identity (typically, the authenticator sends an initial identity/request frame followed by one or more requests for authentication information). Upon receipt of the frame, the supplicant responds with an EAP-response/identity frame.

However, if during bootup, the supplicant does not receive an EAP-request/identity frame from the Wireless AP, the client can initiate authentication by sending an EAPOL-Startframe, which prompts the switch to request the supplicant’s identity. In above case, authenticator co-locate with authentication server. When the supplicant supplies its identity, the authenticator directly exchanges EAPOL to the supplicant until authentication succeeds or fails. If the authentication succeeds, the port becomes authorized. If the authentication fails, the port becomes unauthorized. When the supplicant does not need Wireless access any more, it sends EAPOL-Logoffpacket to terminate its 802.1x session, the port state will become unauthorized. The following figure shows the EAPOL exchange ping-pong chart.

41

All contents copyright (c) 2005 ZyXEL Communications Corporation.

Image 41
Contents Prestige 320W P320W Support Notes Ireless FAQ Trouble Shooting Ethernet connection Internet ConnectionSetting up the Prestige router TCP/IP InstallationTCP/IP Configuration P320W Support Notes P320W Support Notes Configure an Internal Server Behind SUA Smtp Service Port NumberUsing the Dynamic DNS Ddns Snmp Overview Network Management Using SnmpP320W Support Notes SNMPv1 Operations GetNext GetSet TrapZyXEL Snmp Implementation Get Community Configure the Prestige for SnmpTraffic Redirect on LAN port Using Prestige traffic redirectSet Community What is UPnP Using Universal Plug n Play UPnPUsing UPnP in ZyXEL devices Go to Management-UPnP, check Enable UPnP service P320W Support Notes Finally, your video conversation is achieved What is Infrastructure mode? Infrastructure ModeP320W Support Notes Configuration Wireless Station to Infrastructure mode P320W Support Notes Double click on the AP you want to associated with MAC Filter Overview Wireless MAC Address FilteringZyXEL MAC Filter Implementation Configure the Wlan MAC FilterIntroduction WEP ConfigurationP320W Support Notes Setting up the Access Point Setting up the Station Key settingsP320W Support Notes P320W Support Notes Ieee 802.1x Introduction IeeeSupplicant AuthenticatorAuthentication Server Authentication Port State and Authentication Control Re-Authentication Eapol Exchange between 802.1x Authenticator and Supplicant P320W Support Notes Using WEB Configuration Using External Radius Authentication Server P320W Support Notes Site Survey Survey on Site PreparationP320W Support Notes P320W Support Notes What is the P320W 802.11g Wireless Firewall Router? FAQWill the P320W work with my Internet connection? What is PPPoE?What do I need to use the Prestige? Does the Prestige support PPPoE?Why does my provider use PPPoE? How do I know I am using PPPoE?How can I configure the Prestige? Which Internet Applications can I use with the Prestige?How does e-mail work through the Prestige? How fast can the data go? What Dhcp capability does the Prestige support?Your ISP checks the MAC address Your ISP checks the Host Name What is Ddns What is BOOTP/DHCPWhen do I need Ddns service? What are the basic types of firewalls? What is a network firewall?What makes P320W secure? What kind of firewall is the P320W? What is Denials of Service DoS attack?What is Teardrop attack? What is Ping of Death attack?What is SYN Flood attack? What is Land attack?What are the advantages of Wireless LANs? What is IP Spoofing attack?What is a Wireless LAN? What is an Access Point? What are the disadvantages of Wireless LANs?Where can you find wireless 802.11 networks? What is 802.11b? What is Ieee 802.11?What is 802.11a? What is 802.11g?Does the 802.11 interfere with Bluetooth devices? What is Wi-Fi?Can radio signals pass through walls? Is it possible to use products from a variety of vendors?What is Infrastructure mode? What is Ad Hoc mode?How many Access Points are required in a given area? Whats the difference between a Wlan and a WWAN?What is Frequency-hopping Spread Spectrum Technology FHSS? What is Direct-Sequence Spread Spectrum Technology DSSS?Why the 2.4 Ghz Frequency range? What is Server Set ID SSID?What is WEP? What is an ESSID?What is the difference between 40-bit and 64-bit WEP? What is a WEP key?Can the Ssid be encrypted? What is Wireless Sniffer?What are Insertion Attacks? Open SystemWhat is RADIUS? What is 802.1x?What is AAA? Why cannot access the Internet? Why cannot access the Prestige from my computer?Your ISP checks the MAC address Application Outgoing Connection Incoming Connection Unable to run applicationsZyXEL SUA Supporting Table NAT-T P320W Support Notes