POEGEM12T2SFP User Manual

The overview of the 802.1x operation shown in Fig. 3-59 is quite simple. When the Supplicant PAE issues a request to the Authenticator PAE, the Authenticator and the Supplicant exchange authentication messages. Then, the Authenticator passes the request to the RADIUS server to verify the username and password. Finally, the RADIUS server replies if the request is granted or denied.

While in the authentication process, the message packets, encapsulated by Extensible Authentication Protocol over LAN (EAPOL), are exchanged between an authenticator PAE and a supplicant PAE. The Authenticator exchanges the messages to the authentication server using EAP encapsulation. Before successfully authenticating, the supplicant can only communicate with the authenticator to perform the authentication message exchange or access the network from an uncontrolled port.

Supplicant’s

System

Supplicant

PAE

Authenticator’s System

Services Offered

 

 

by Authenticator

 

Authenticator

(e.g Bridge Relay)

 

PAE

 

 

 

Controlled port

Uncontrolled port

Port Authorize

MAC Enable

Authentication

Server’s System

Authentication

Server

LAN

Fig. 3-59

95 Alloy Computer Products Pty Ltd Copyright ©2006

Page 99
Image 99
Alloy Computer Products POEGEM12T2SFP user manual Lan