User's Manual

Table Of Contents
Configuration Guide of XGS-5240-Series
47-6
Fig 3-5 the Format of Data Domain in Request and Response Packets
Identifier: to assist matching the Request and Response messages.
Length: the length of the EAP packet, covering the domains of Code, Identifier, Le
ngth and Data, in byte.
Data: the content of the EAP packet, depending on the Code type.
47.1.4 The Encapsulation of EAP Attributes
RADIUS adds two attribute to support EAP authentication: EAP-Message and Mess
age-Authenticator. Please refer to the Introduction of RADIUS protocol in “AAA-RADIUS-
HWTACACS operation” to check the format of RADIUS messages.
1. EAP-Message
As illustrated in the next figure, this attribute is used to encapsulate EAP packet, t
he type code is 79, String domain should be no longer than 253 bytes. If the data len
gth in an EAP packet is larger than 253 bytes, the packet can be divided into fragmen
ts, which then will be encapsulated in several EAP-Messages attributes in their original
order.
Fig 3-6 the Encapsulation of EAP-Message Attribute
2. Message-Authenticator
As illustrated in the next figure, this attribute is used in the process of using authe
ntication methods like EAP and CHAP to prevent the access request packets from bein
g eavesdropped. Message-Authenticator should be included in the packets containing th
e EAP-Message attribute, or the packet will be dropped as an invalid one.
Fig 3-7 Message-Authenticator Attribute