Users Guide

Table Of Contents
6. If the identity information the supplicant provides is valid, the authentication server sends an Access Accept frame that
specifies the network privileges. The authenticator changes the port state to authorize and forwards an EAP Success frame.
If the identity information is invalid, the server sends an Access Reject frame. If the port state remains unauthorized, the
authenticator forwards an EAP Failure frame.
EAP over RADIUS
802.1X uses RADIUS to transfer EAP packets between the authenticator and the authentication server. EAP messages are
encapsulated in RADIUS packets as an attribute of type, length, value (TLV) formatthe type value for EAP messages is 79.
Configure 802.1X
You can configure and enable 802.1X on a port in a single process. OS10 supports 802.1X with EAP-MD5, EAP-TLS, and EAP-
TTLS. All platforms support RADIUS as the authentication server.
If the primary RADIUS server becomes unresponsive, the authenticator begins using a secondary RADIUS server if configured.
NOTE: 802.1X is not supported on port channels or port channel members.
434 Layer 2