XGS-5240-Series User Manual

Table Of Contents
Configuration Guide of XGS-5240-Series
47-3
The PAE of the authenticator system authenticates the supplicant systems needing
to access the LAN via the authentication server system, and deal with the authenti
cated/unauthenticated state of the controlled port according to the result of the aut
hentication. The authenticated state means the user is allowed to access the netw
ork resources, the unauthenticated state means only the EAPOL messages are allo
wed to be received and sent while the user is forbidden to access network resourc
es.
2. controlled/uncontrolled ports
The authenticator system provides ports to access the LAN for the supplicant syste
ms. These ports can be divided into two kinds of logical ports: controlled ports and unc
ontrolled ports.
The uncontrolled port is always in bi-directionally connected status, and mainly use
d to transmit EAPOL protocol frames, to guarantee that the supplicant systems can
always send or receive authentication messages.
The controlled port is in connected status authenticated to transmit service messag
es. When unauthenticated, no message from supplicant systems is allowed to be r
eceived.
The controlled and uncontrolled ports are two parts of one port, which means each
frame reaching this port is visible on both the controlled and uncontrolled ports.
3. Controlled direction
In unauthenticated status, controlled ports can be set as unidirectional controlled or
bi-directionally controlled.
When the port is bi-directionally controlled, the sending and receiving of all frames
is forbidden.
When the port is unidirectional controlled, no frames can be received from the sup
plicant systems while sending frames to the supplicant systems is allowed.
Notes: At present, this kind of switch only supports unidirectional control.
47.1.2 The Work Mechanism of 802.1x
IEEE 802.1x authentication system uses EAP (Extensible Authentication Protocol) to
implement exchange of authentication information between the supplicant system, auth
enticator system and authentication server system.