Chapter12
DOT1XConfiguration
TableofContents
DOT1xOverview.............................................................129
ConguringDOT1X..........................................................130
DOT1XCongurationExample...........................................137
DOT1XMaintenanceandDiagnosis....................................140
DOT1xOverview
DOT1X,IEEE802.1x,isaport-basednetworkaccesscontrolpro-
tocol.Itoptimizestheauthenticationmodeandauthentication
architectureandsolvestheproblemscausedbytraditionalPPPoE
andWeb/Portalauthenticationmodes,thereforeitismoresuitable
forthebroadbandEthernet.
IEEE802.1xprotocolarchitecturecontainsthreemajorparts:
SupplicantSystem,AuthenticatorSystemandAuthentication
ServerSystem.
1.Generallyclientsystemisauserterminalsystemwhereclient
softwareisofteninstalled.UseroriginatesIEEE802.1xprotocol
authenticationbybootingtheclientsoftware.Tosupportport-
basedaccesscontrol,theclientsystemneedstosupportthe
ExtensibleAuthenticationProtocolOverLAN(EAPOL).
2.Authenticationsystemisnetworkequipmentsupportingthe
IEEE802.1xprotocol,suchastheswitch.Theequipmentcor-
respondstodifferentuserports(physicalportorMACaddress,
VLANandIPoftheuserequipment)andhastwologicalports
composedofthecontrolledportanduncontrolledport.
�Uncontrolledportisalwaysinbidirectionalconnectionstate
anddeliversEAPOLprotocol,whichensurestheclientto
alwayssendorreceiveauthentication.
�Controlledportopensuponsuccessoftheauthentication
todelivernetworkresourcesandservices.Thecontrolled
portmodescanbeconguredasbidirectionalcontrolled
andonlytransmissioncontrolledtoadapttodifferentap-
plicationenvironments.Iftheuserfailstopassauthentica-
tion,thecontrolledportisinunauthenticatedstateandthe
usercannotaccessservicesofferedbytheauthentication
system.
ControlledportanduncontrolledportintheIEEE802.1xpro-
tocolarelogicalconceptsandsuchphysicalswitchesareinex-
istentintheequipment.TheIEEE802.1xprotocolestablishes
CondentialandProprietaryInformationofZTECORPORATION129