Chapter11
DOT1xConfiguration
TableofContents
DOT1xOverview.............................................................113
ConguringDOT1x..........................................................114
DOT1xCongurationExamples..........................................117
DOT1xMaintenanceandDiagnosis.....................................120
DOT1xOverview
DOT1XisIEEE802.1x,isaport-basednetworkaccesscontrolpro-
tocol.Itoptimizestheauthenticationmodeandauthentication
architectureandsolvestheproblemscausedbytraditionalPPPoE
andWeb/Portalauthenticationmodes;thereforeitismoresuit-
ableforthebroadbandEthernet.
IEEE802.1xprotocolarchitecturecontainsthreemajorparts:sup-
plicantsystem,authenticatorsystemandauthenticationserver
system.
SupplicantSystemClientsystemisauserterminalsystemwhereclientsoftwareis
ofteninstalled.UseroriginatesIEEE802.1xprotocolauthentica-
tionbybootingtheclientsoftware.Tosupportport-basedaccess
control,theclientsystemneedstosupporttheExtensibleAuthen-
ticationProtocolOverLAN(EAPOL).
Authentication
System
Authenticationsystemisnetworkequipmentsupportingthe
IEEE802.1xprotocol,suchastheswitch.Correspondingtoevery
differentuserport(physicalportorMACaddress,VLANandIP
oftheuserequipment),theequipmenthastwologicalports
composedofthecontrolledportanduncontrolledport.
Uncontrolledportisalwaysinbidirectionalconnectionstateand
deliversEAPOLprotocolframesthusensuringtheclienttoalways
sendorreceiveauthentication.
Controlledportopensuponsuccessoftheauthenticationandde-
liversnetworkresourcesandservices.Thecontrolledportmodes
canbeconguredasbidirectionalcontrolandonlyindirectioncon-
troltoadapttodifferentapplicationenvironments.Whentheuser
failstopassauthentication,thecontrolledportisinunauthenti-
catedstateandtheusercannotaccessservicesofferedbythe
authenticationsystem.
ControlledanduncontrolledportsintheIEEE802.1xprotocolare
logicalconceptsandsuchphysicalswitchesareinexistentinthe
equipment.TheIEEE802.1xprotocolestablishesalogicalau-
CondentialandProprietaryInformationofZTECORPORATION113