ZXR102900ESeriesCongurationGuide
physicalportsorMACaddress,VLAN,orIPaddressoftheuserequipment),the
authenticationsystemhastwologicalports:controlledportanduncontrolledport.
1.Theuncontrolledportisalwaysinthestatethatthebidirectionalconnectionsare
available.ItisusedtotransfertheEAPOLframesandcanensurethattheclient
canalwayssendorreceivetheauthentication.
2.Thecontrolportisenabledonlywhentheauthenticationispassed.Itisusedto
transferthenetworkresourceandservices.Thecontrolledportcanbecongured
asbidirectionalcontrolledorinputcontrolledtomeettherequirementofdifferent
applications.Ifthesubscriberauthenticationisnotpassed,thissubscribercannot
visittheservicesprovidedbytheauthenticationsystem.
3.ThecontrolledportanduncontrolledportintheIEEE802.1xprotocolarelogical
ports.Therearenosuchphysicalportsontheequipment.TheIEEE802.1x
protocolsetsupalocalauthenticationchannelforeachsubscriberandother
subscriberscannotuseit.Thus,preventingtheportfrombeingusedbyother
subscribersaftertheportisenabled.
lTheauthenticationserverisaRADIUSserver.Thisservercanstorealotof
subscriberinformation,suchastheVLANthatthesubscriberbelongsto,CAR
parameters,priority,andsubscriberaccesscontrollist.Aftertheauthentication
ofasubscriberispassed,theauthenticationserverwillpasstheinformationof
thissubscribertotheauthenticationsystem,whichwillcreateadynamicaccess
controllist.Thesubsequentowofthesubscriberwillbemonitoredbytheabove
parameters.TheauthenticationsystemcommunicateswiththeRADIUSserver
throughtheRADIUSprotocol.
RADIUSisaprotocolstandardusedfortheauthentication,authorization,andexchange
ofcongurationdatabetweentheRadiusserverandRadiusclient.
RADIUSusestheClient/Servermode.TheClientrunsontheNAS.Itisresponsible
forsendingthesubscriberinformationtothespeciedRadiusserverandcarryingout
operationsaccordingtotheresultreturnedbytheserver.
TheRadiusAuthenticationServerisresponsibleforreceivingthesubscriberconnection
request,verifyingthesubscriberidentity,andreturningthecongurationinformation
requiredbythecustomer.ARadiusAuthenticationServercanserveasaRADIUS
customerproxytoconnecttoanotherRadiusAuthenticationServer.
TheRadiusAccountingServerisresponsibleforreceivingthesubscriberbillingstart
requestandsubscriberbillingstoprequest,andcompletingthebillingfunction.
TheNAScommunicateswiththeRadiusServerthroughRADIUSpackets.Attributesin
theRADIUSpacketsareusedtotransferthedetailedauthentication,authorization,and
billinginformation.
TheEAPprotocolisusedbetweentheswitchandthesubscriber.Threetypesofidentity
authenticationmethodsareprovidedbetweentheRADIUSservers:PAP ,CHAP ,and
EAP-MD5.Anyofthemethodscanbeusedaccordingtodifferentserviceoperation
requirements.
lPasswordAuthenticationProtocol(PAP)
5-72
SJ-20130731155059-002|2013-11-27(R1.0)ZTEProprietaryandCondential