Specifications

Authentication Overview
April 15, 2011 Page 3 of 36
IEEE 802.1x Using EAP
TheIEEE802.1xportbasedaccesscontrolstandardallowsyoutoauthenticateandauthorizeuser
accesstothenetworkattheportlevel.Accesstotheswitchportsiscentrallycontrolledfroman
authenticationserverusingRADIUS.TheExtensibleAuthenticationProtocol(EAP),definedin
RFC3748,providesthemeansforcommunicating
theauthenticationinformation.
TherearethreesupportedtypesofEAP:
•MD5EAPMD5isachallengehandshakeprotocoloverEAPthatauthenticatestheuser
withanormalusernameandpassword.
•TLSEAPTLSprovidesatransportlayersecuritybaseduponthepresentationand
acceptanceofdigitalcertificatesbetweenthe
supplicantandtheauthenticationserver.
ProtectedProtectedExtensibleAuthenticationProtocol(PEAP)optionallyauthenticatesthe
authenticationservertotheclientusinganX509certificateusingaTLStunnel,afterwhich
theclientauthenticationcredentialsareexchanged.
AllEnterasysplatformssupportIEEE802.1x,whichprotectsagainstunauthorizedaccesstoa
network,DoSattacks,theftofservicesanddefacementofcorporatewebpages.
802.1xconfigurationconsistsofsettingport,global802.1xparam eters,andRADIUSparameters
ontheswitchestopointtheswitchtotheauthenticationserver.TheFilterIDRADIUSattribute
canbeconfiguredontheauthenticationservertodirectdynamicpolicy
assignmentontheswitch
tothe802.1xauthentica ting endsystem.
MAC-Based Authentication (MAC)
MACbasedauthentication(MAC)au thenticatesadeviceusingthesourceMACaddressof
receivedpackets.TheauthenticatorsendstheauthenticationserverasourceMACaddressasthe
usernameandapasswordthatyouconfigureontheswitch.Iftheauthenticationserverreceives
validcredentialsfromtheswitch,RADIUSreturnsan
Acceptmessagetotheswitch.MAC
authenticationenablesswitchestoauthenticateendsystems,suchasprintersandcamcorder
devicesthatdonotsupport802.1xorwebauthenticati on.SinceMACbasedauthentication
authenticatesthedevice,notthe user,andissubjecttoMACaddressspoofingattacks,itshould
notbeconsidered
asecureauthentica tionmethod.However,itdoesprovidealevelof
authenticationforadevicewhereotherwisenonewouldbepossible.
Themodularswitch,stackablefixedswitch,andstandalonefixedswitchdevicessupport
MACbasedauthentica tion.
Port Web Authentication (PWA)
PortWebAuthentication (PWA)authenticatesauserbyutilizingawebbrowserforthelogin
processtoauthenticatetothenetwork.TologinusingPWA,auseropensthewebbrowser
requestingaURLthateitherdirectlyaccessesthePWAloginpageorisautomaticallyredirectedto
theloginpage.
AtthePWAloginpage,theuserentersaloginusernameandpassword.Onthe
switch,eithertheChallengeHandshakeAu thenticationProtocol(CHAP)orthePassword
AuthenticationProtocol(PAP)verifiestheusernameandpasswordcredentialsprovidedtothe
authenticationserver.Ifthecredentialsarevalidated,theauthenticationserverreturnsa
RADIUS
Acceptmessage,optionallycontainingFilterIDortunnelattributes,totheswitch.
PAPusesanunencryptedpassword.CHAPusesthepasswordtogenerateadigestthatis
transmittedtotheauthenticationserver.IfRADIUSdeterminesthatthedigestmatchesthedigest
generatedontheauthenticationserver,accessisgranted.The
acceptancemessagebacktothe