POEGEM12T2SFP User Manual 95 Alloy Computer Products Pty Ltd Copyright ©2006
The overview of the 802.1x operation shown in Fig. 3-59 is quite simple. When the Supplicant
PAE issues a request to the Authenticator PAE, the Authenticator and the Supplicant exchange
authentication messages. Then, the Authenticator passes the request to the RADIUS server to
verify the username and password. Finally, the RADIUS server replies if the request is granted or
denied.
While in the authentication process, the message packets, encapsulated by Extensible
Authentication Protocol over LAN (EAPOL), are exchanged between an authenticator PAE and a
supplicant PAE. The Authenticator exchanges the messages to the authentication server using
EAP encapsulation. Before successfully authenticating, the supplicant can only communicate
with the authenticator to perform the authentication message exchange or access the network
from an uncontrolled port.
Fig. 3-59
LAN
Authenticator
PAE
Services Offered
by Authenticator
(e.g Bridge Relay)
A
uthenticator’s System Authentication
Server’s System
Authentication
Server
Supplicant
PAE
Supplicant’s
System
Uncontrolled port Controlled port
MAC Enable
Port Authorize