Chapter4ServiceConguration
lTheauthenticationsystemisgenerallynetworkequipmentthatsupportsthe
IEEE802.1xprotocol,forexample,theswitch.Correspondingtotheportsofdifferent
subscribers(theportscouldbephysicalportsorMACaddress,VLAN,orIPaddress
oftheuserequipment),theauthenticationsystemhastwologicalports:controlled
portanduncontrolledport.
1.Theuncontrolledportisalwaysinthestatethatthebidirectionalconnectionsare
available.ItisusedtotransfertheEAPOLframesandcanensurethattheclient
canalwayssendorreceivetheauthentication.
2.Thecontrolportisenabledonlywhentheauthenticationispassed.Itisusedto
transferthenetworkresourceandservices.Thecontrolledportcanbecongured
asbidirectionalcontrolledorinputcontrolledtomeettherequirementofdifferent
applications.Ifthesubscriberauthenticationisnotpassed,thissubscribercannot
visittheservicesprovidedbytheauthenticationsystem.
3.ThecontrolledportanduncontrolledportintheIEEE802.1xprotocolarelogical
ports.Therearenosuchphysicalportsontheequipment.TheIEEE802.1x
protocolsetsupalocalauthenticationforeachsubscriberthatothersubscribers
cannotuse.Thus,therewillnotbesuchaproblemthattheportisusedbyother
subscribersaftertheportisenabled.
lTheauthenticationserverisgenerallyaRADIUSserver.Thisservercanstorea
lotofsubscriberinformation,suchasVLANthatthesubscriberbelongsto,CAR
parameters,priority,subscriberaccesscontrollist,andsoon.Aftertheauthentication
ofasubscriberispassed,theauthenticationserverwillpasstheinformationof
thissubscribertotheauthenticationsystem,whichwillcreateadynamicaccess
controllist.Thesubsequentowofthesubscriberwillbemonitoredbytheabove
parameters.TheauthenticationsystemcommunicateswiththeRADIUSserver
throughtheRADIUSprotocol.
RADIUSisaprotocolstandardusedfortheauthentication,authorization,andexchange
ofcongurationdatabetweentheRadiusserverandRadiusclient.
RADIUSadoptstheClient/Servermode.TheClientrunsontheNAS.Itisresponsible
forsendingthesubscriberinformationtothespeciedRadiusserverandcarryingout
operationsaccordingtotheresultreturnedbytheserver.
TheRadiusAuthenticationServerisresponsibleforreceivingthesubscriberconnection
request,verifyingthesubscriberidentity,andreturningthecongurationinformation
requiredbythecustomer.ARadiusAuthenticationServercanserveasaRADIUS
customerproxytoconnecttoanotherRadiusAuthenticationServer.
TheRadiusAccountingServerisresponsibleforreceivingthesubscriberbillingstart
requestandsubscriberbillingstoprequest,andcompletingthebillingfunction.
TheNAScommunicateswiththeRadiusServerthroughRADIUSpackets.Attributesinthe
RADIUSpacketsareusedtotransferthedetailedauthentication,authorization,andbilling
information.Theattributesusedbythisswitchareprimarilystandardattributesdenedin
therfc2865,rfc2866,andrfc2869.
TheEAPprotocolisusedbetweentheswitchandthesubscriber.Threetypesofidentity
authenticationmethodsareprovidedbetweentheRADIUSservers:PAP ,CHAP,and
4-67
SJ-20120409144109-002|2012-07-02(R1.0)ZTEProprietaryandCondential