R0106-HP MSR Router Series Security Configuration Guide(V7)

69
Performs unidirectional traffic control to deny traffic from the client. The HP devices support
only unidirectional traffic control.
Figure 23 Authorization state of a controlled port
802.1X-related protocols
802.1X uses the Extensible Authentication Protocol (EAP) to transport authentication information for the
client, the network access device, and the authentication server. EAP is an authentication framework that
uses the client/server model. The framework supports a variety of authentication methods, including
MD5-Challenge, EAP-Transport Layer Security (EAP-TLS), and Protected EAP (PEAP).
802.1X defines EAP over LAN (EAPOL) for passing EAP packets between the client and the network
access device over a wired or wireless LAN. Between the network access device and the authentication
server, 802.1X delivers authentication information by using one of the following methods:
Encapsulates EAP packets in RADIUS by using EAP over RADIUS (EAPOR), as described in "EAP
re
lay."
Extracts authentication information from the EAP packets and encapsulates the information in
standard RADIUS packets, as described in "EAP termination."
Packet formats
EAP packet format
Figure 24 shows the EAP packet format.
Figure 24 EAP packet format
Code—Type of the EAP packet. Options include Request (1), Response (2), Success (3), or Failure
(4).