How 802.1X port security works

FIGURE 3 Controlled and uncontrolled ports before and after client authentication

Authentication

Authentication

Server

Server

PAE

Brocade Switch (Authenticator)

Uncontrolled Port

Physical Port

 

 

 

 

 

 

 

 

 

Services

 

 

 

 

PAE

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Controlled Port

Uncontrolled Port

 

(Unauthorized)

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Physical Port

Services

Brocade Switch (Authenticator)

Controlled Port

(Authorized)

PAE

802.1X-Enabled

Supplicant

PAE

802.1X-Enabled

Supplicant

Before Authentication

After Authentication

Before a Client is authenticated, only the uncontrolled port on the Authenticator is open. The uncontrolled port allows only EAPOL frames to be exchanged between the Client and the Authentication Server. The controlled port is in the unauthorized state and allows no traffic to pass through.

During authentication, EAPOL messages are exchanged between the Supplicant PAE and the Authenticator PAE, and RADIUS messages are exchanged between the Authenticator PAE and the Authentication Server.Refer to “Message exchange during authentication” on page 157 for an example of this process. If the Client is successfully authenticated, the controlled port becomes authorized, and traffic from the Client can flow through the port normally.

By default, all controlled ports on the Brocade device are placed in the authorized state, allowing all traffic. When authentication is activated on an 802.1X-enabled interface, the interface controlled port is placed initially in the unauthorized state. When a Client connected to the port is successfully authenticated, the controlled port is then placed in the authorized state until the Client logs off.

Refer to “Enabling 802.1X port security” on page 174 for more information.

156

Brocade ICX 6650 Security Configuration Guide

 

53-1002601-01

Page 176
Image 176
Brocade Communications Systems 6650 manual Pae