Users Guide

Success frame. If the identity information is invalid, the server sends an Access-Reject frame. If the port state remains
unauthorized, the authenticator forwards an EAP Failure frame.
Figure 4. EAP Port-Authentication
EAP over RADIUS
802.1X uses RADIUS to shuttle EAP packets between the authenticator and the authentication server, as defined in RFC 3579.
EAP messages are encapsulated in RADIUS packets as a type of attribute in Type, Length, Value (TLV) format. The Type value for
EAP messages is 79.
Figure 5. EAP Over RADIUS
802.1X 85