User's Manual

Table Of Contents
Users Manual of SGS-5240 Series Managed Switch
219
4.7.3 802.1X
Overview of 802.1X (Port-Based) Authentication
In the 802.1X-world, the user is called the supplicant, the switch is the authenticator, and the RADIUS server is the
authentication server. The switch acts as the man-in-the-middle, forwarding requests and responses between the supplicant
and the authentication server.
Frames sent between the supplicant and the switch are special 802.1X frames, known as EAPOL (EAP Over LANs) frames.
EAPOL frames encapsulate EAP PDUs (RFC3748). Frames sent between the switch and the RADIUS server are RADIUS
packets. RADIUS packets also encapsulate EAP PDUs together with other attributes like the switch's IP address, name, and the
supplicant's port number on the switch. EAP is very flexible, in that it allows for different authentication methods, like
MD5-Challenge, PEAP, and TLS. The important thing is that the authenticator (the switch) doesn't need to know which
authentication method the supplicant and the authentication server are using, or how many information exchange frames are
needed for a particular method. The switch simply encapsulates the EAP part of the frame into the relevant type (EAPOL or
RADIUS) and forwards it.
When authentication is complete, the RADIUS server sends a special packet containing a success or failure indication. Besides
forwarding this decision to the supplicant, the switch uses it to open up or block traffic on the switch port connected to the
supplicant.
4.7.3.1 Global Configuration
Security > 802.1x > Global Configuration page is used to configure the global parameter of 802.1x.
802.1X Status Sets the global setting for 802.1X. (Default: Disabled)
EAPOL Pass-through Passes EAPOL frames through all ports in STP forwarding state when dot1x is globally disabled.
(Default: Disabled)