SlideShare a Scribd company logo
1 of 1
IEEE 802.1X                                                                                            packetlife.net
                      802.1X Header                                                Terminology
     1           1                 2                        Extensible Authentication Protocol (EAP)
  Version       Type             Length             EAP     A flexible authentication framework defined in RFC 3748
                                                            EAP Over LANs (EAPOL)
                                                            EAP encapsulated by 802.1X for transport across LANs
                       EAP Header
                                                            Supplicant
    1             1                2
                                                            The device (client) attached to an access link that requests
   Code       Identifier         Length             Data    authentication by the authenticator
                                                            Authenticator
                      EAP Flow Chart                        The device that controls the status of a link; typically a
                                                            wired switch or wireless access point
                                          Authentication
Supplicant            Authenticator          Server      Authentication Server
                                                         A backend server which authenticates the credentials
                                                         provided by supplicants (for example, a RADIUS server)
                                                            Guest VLAN
                                                            Fallback VLAN for clients not 802.1X-capable
                                                            Restricted VLAN
      Identity Request
                                                            Fallback VLAN for clients which fail authentication

                                                               802.1X Packet Types                   EAP Codes
     Identity Response            Access Request
                                                            0 EAP Packet                      1 Request

     Challenge Request           Access Challenge           1 EAPOL-Start                     2 Response
                                                            2 EAPOL-Logoff                    3 Success
    Challenge Response            Access Request            3 EAPOL-Key                       4 Failure
                                                            4 EAPOL-Encap-ASF-Alert            EAP Req/Resp Types
            Success               Access Accept
                                                                Interface Defaults               1 Identity
                           EAP                RADIUS          Max Auth Requests 2                2 Notification

                      Configuration                              Reauthentication Off            3 Nak
                                                                      Quiet Period 60s           4 MD5 Challenge
! Define a RADIUS server      Global Configuration
radius-server host 10.0.0.100                                       Reauth Period 1hr            5 One Time Password
radius-server key MyRadiusKey
! Configure 802.1X to authenticate via AAA
                                                                   Server Timeout 30s            6 Generic Token Card
aaa new-model                                                 Supplicant Timeout 30s          254 Expanded Types
aaa authentication dot1x default group radius
! Enable 802.1X authentication globally                                   Tx Period 30s       255 Experimental
dot1x system-auth-control
                                                                              Port-Control Options
! Static access mode              Interface Configuration
                                                            force-authorized
switchport mode access
! Enable 802.1X authentication per port
                                                            Port will always remain in authorized state (default)
dot1x port-control auto                                     force-unauthorized
! Configure host mode (single or multi)                     Always unauthorized; authentication attempts are ignored
dot1x host-mode single-host
! Configure maximum authentication attempts                 auto
dot1x max-reauth-req                                        Supplicants must authenticate to gain access
! Enable periodic reauthentication
dot1x reauthentication                                                           Troubleshooting
! Configure a guest VLAN
dot1x guest-vlan 123                                        show dot1x [statistics] [interface <interface>]
! Configure a restricted VLAN                               dot1x test eapol-capable [interface <interface>]
dot1x auth-fail vlan 456
dot1x auth-fail max-attempts 3                              dot1x re-authenticate interface <interface>


by Jeremy Stretch                                                                                                    v2.0

More Related Content

What's hot

CCA security answers chapter 2 test
CCA security answers chapter 2 testCCA security answers chapter 2 test
CCA security answers chapter 2 testSoporte Yottatec
 
Microsoft lync server 2010 protocol workloads poster
Microsoft lync server 2010 protocol workloads posterMicrosoft lync server 2010 protocol workloads poster
Microsoft lync server 2010 protocol workloads posterbigwalker
 
operating and configuring cisco a cisco IOS device
operating and configuring cisco a cisco IOS deviceoperating and configuring cisco a cisco IOS device
operating and configuring cisco a cisco IOS devicescooby_doo
 
How to Configure QinQ?
How to Configure QinQ?How to Configure QinQ?
How to Configure QinQ?Huanetwork
 
FlexVPNLabHandbook-SAMPLE
FlexVPNLabHandbook-SAMPLEFlexVPNLabHandbook-SAMPLE
FlexVPNLabHandbook-SAMPLETariq Sheikh
 
第6讲 操作与配置Cisco Ios
第6讲 操作与配置Cisco Ios第6讲 操作与配置Cisco Ios
第6讲 操作与配置Cisco IosF.l. Yu
 
Cisco CCNA Security 210-260 Practice Exam
Cisco CCNA Security 210-260 Practice ExamCisco CCNA Security 210-260 Practice Exam
Cisco CCNA Security 210-260 Practice ExamJysmeen
 
Solarwinds port requirement
Solarwinds port requirementSolarwinds port requirement
Solarwinds port requirementEzahir Amer
 
Ccna icnd2-labs exercices
Ccna icnd2-labs exercicesCcna icnd2-labs exercices
Ccna icnd2-labs exercicessaqrjareh
 

What's hot (12)

CCA security answers chapter 2 test
CCA security answers chapter 2 testCCA security answers chapter 2 test
CCA security answers chapter 2 test
 
Basics to Configure NW Device
Basics to Configure NW DeviceBasics to Configure NW Device
Basics to Configure NW Device
 
Microsoft lync server 2010 protocol workloads poster
Microsoft lync server 2010 protocol workloads posterMicrosoft lync server 2010 protocol workloads poster
Microsoft lync server 2010 protocol workloads poster
 
operating and configuring cisco a cisco IOS device
operating and configuring cisco a cisco IOS deviceoperating and configuring cisco a cisco IOS device
operating and configuring cisco a cisco IOS device
 
How to Configure QinQ?
How to Configure QinQ?How to Configure QinQ?
How to Configure QinQ?
 
FlexVPNLabHandbook-SAMPLE
FlexVPNLabHandbook-SAMPLEFlexVPNLabHandbook-SAMPLE
FlexVPNLabHandbook-SAMPLE
 
第6讲 操作与配置Cisco Ios
第6讲 操作与配置Cisco Ios第6讲 操作与配置Cisco Ios
第6讲 操作与配置Cisco Ios
 
Cisco CCNA Security 210-260 Practice Exam
Cisco CCNA Security 210-260 Practice ExamCisco CCNA Security 210-260 Practice Exam
Cisco CCNA Security 210-260 Practice Exam
 
Solarwinds port requirement
Solarwinds port requirementSolarwinds port requirement
Solarwinds port requirement
 
Ccna icnd2-labs exercices
Ccna icnd2-labs exercicesCcna icnd2-labs exercices
Ccna icnd2-labs exercices
 
p10
p10p10
p10
 
Is is
Is isIs is
Is is
 

Similar to Ieee 802.1 x

Ieee 802.1 x
Ieee 802.1 xIeee 802.1 x
Ieee 802.1 xmatoko
 
At8000 s configurando_8021x
At8000 s configurando_8021xAt8000 s configurando_8021x
At8000 s configurando_8021xNetPlus
 
IEEE 802.1X and Axis’ Implementation
IEEE 802.1X and Axis’ ImplementationIEEE 802.1X and Axis’ Implementation
IEEE 802.1X and Axis’ ImplementationAxis Communications
 
8021x feature config_guide
8021x feature config_guide8021x feature config_guide
8021x feature config_guideWilson Ospina
 
Implementing 802.1x Authentication
Implementing 802.1x AuthenticationImplementing 802.1x Authentication
Implementing 802.1x Authenticationdkaya
 
Configuring Wired 802.1x Authentication on Windows Server 2012.pdf
Configuring Wired 802.1x Authentication on Windows Server 2012.pdfConfiguring Wired 802.1x Authentication on Windows Server 2012.pdf
Configuring Wired 802.1x Authentication on Windows Server 2012.pdfdjameleddine2015
 
Wireless Security Policy
Wireless Security PolicyWireless Security Policy
Wireless Security Policyserpentine707
 
Disobey 2024: Karri Huhtanen: Wi-Fi Roaming Security and Privacy
Disobey 2024: Karri Huhtanen: Wi-Fi Roaming Security and PrivacyDisobey 2024: Karri Huhtanen: Wi-Fi Roaming Security and Privacy
Disobey 2024: Karri Huhtanen: Wi-Fi Roaming Security and PrivacyKarri Huhtanen
 
Hacking wireless networks
Hacking wireless networksHacking wireless networks
Hacking wireless networksSahil Rai
 
802.1x Authentication Standard
802.1x Authentication Standard802.1x Authentication Standard
802.1x Authentication StandardDan Miller
 
802 11 3
802 11 3802 11 3
802 11 3rphelps
 
Troubleshooting Novell Access Manager 3.1
Troubleshooting Novell Access Manager 3.1Troubleshooting Novell Access Manager 3.1
Troubleshooting Novell Access Manager 3.1Novell
 
EAP-TLS (extended version)
EAP-TLS (extended version)EAP-TLS (extended version)
EAP-TLS (extended version)Karri Huhtanen
 
Windows Server 2008 R2 Overview
Windows Server 2008 R2 OverviewWindows Server 2008 R2 Overview
Windows Server 2008 R2 OverviewSteven Wilder
 

Similar to Ieee 802.1 x (20)

Ieee 802.1 x
Ieee 802.1 xIeee 802.1 x
Ieee 802.1 x
 
At8000 s configurando_8021x
At8000 s configurando_8021xAt8000 s configurando_8021x
At8000 s configurando_8021x
 
Sw8021x
Sw8021xSw8021x
Sw8021x
 
IEEE 802.1X and Axis’ Implementation
IEEE 802.1X and Axis’ ImplementationIEEE 802.1X and Axis’ Implementation
IEEE 802.1X and Axis’ Implementation
 
8021x feature config_guide
8021x feature config_guide8021x feature config_guide
8021x feature config_guide
 
Implementing 802.1x Authentication
Implementing 802.1x AuthenticationImplementing 802.1x Authentication
Implementing 802.1x Authentication
 
Configuring Wired 802.1x Authentication on Windows Server 2012.pdf
Configuring Wired 802.1x Authentication on Windows Server 2012.pdfConfiguring Wired 802.1x Authentication on Windows Server 2012.pdf
Configuring Wired 802.1x Authentication on Windows Server 2012.pdf
 
IEEE 802.1 x
IEEE 802.1 xIEEE 802.1 x
IEEE 802.1 x
 
Wireless Security Policy
Wireless Security PolicyWireless Security Policy
Wireless Security Policy
 
Disobey 2024: Karri Huhtanen: Wi-Fi Roaming Security and Privacy
Disobey 2024: Karri Huhtanen: Wi-Fi Roaming Security and PrivacyDisobey 2024: Karri Huhtanen: Wi-Fi Roaming Security and Privacy
Disobey 2024: Karri Huhtanen: Wi-Fi Roaming Security and Privacy
 
Hacking wireless networks
Hacking wireless networksHacking wireless networks
Hacking wireless networks
 
802.1x Authentication Standard
802.1x Authentication Standard802.1x Authentication Standard
802.1x Authentication Standard
 
802 11 3
802 11 3802 11 3
802 11 3
 
Troubleshooting Novell Access Manager 3.1
Troubleshooting Novell Access Manager 3.1Troubleshooting Novell Access Manager 3.1
Troubleshooting Novell Access Manager 3.1
 
Iuwne10 S04 L04
Iuwne10 S04 L04Iuwne10 S04 L04
Iuwne10 S04 L04
 
11 01 Tbd I Radius Security
11 01 Tbd I Radius Security11 01 Tbd I Radius Security
11 01 Tbd I Radius Security
 
EAP-TLS (extended version)
EAP-TLS (extended version)EAP-TLS (extended version)
EAP-TLS (extended version)
 
Privileged Access Manager POC Guidelines
Privileged Access Manager  POC GuidelinesPrivileged Access Manager  POC Guidelines
Privileged Access Manager POC Guidelines
 
Jetty TLS troubleshooting
Jetty TLS troubleshootingJetty TLS troubleshooting
Jetty TLS troubleshooting
 
Windows Server 2008 R2 Overview
Windows Server 2008 R2 OverviewWindows Server 2008 R2 Overview
Windows Server 2008 R2 Overview
 

More from Mohamed Gamel (20)

Vyatta subnet range_cheat_sheet
Vyatta subnet range_cheat_sheetVyatta subnet range_cheat_sheet
Vyatta subnet range_cheat_sheet
 
Voip basics
Voip basicsVoip basics
Voip basics
 
Vla ns
Vla nsVla ns
Vla ns
 
Tcpdump
TcpdumpTcpdump
Tcpdump
 
Spanning tree
Spanning treeSpanning tree
Spanning tree
 
Scapy
ScapyScapy
Scapy
 
Rip
RipRip
Rip
 
Qo s
Qo sQo s
Qo s
 
Ppp
PppPpp
Ppp
 
Physical terminations
Physical terminationsPhysical terminations
Physical terminations
 
Ospf
OspfOspf
Ospf
 
Nat
NatNat
Nat
 
Media wiki
Media wikiMedia wiki
Media wiki
 
Markdown
MarkdownMarkdown
Markdown
 
I pv6
I pv6I pv6
I pv6
 
I pv4 subnetting
I pv4 subnettingI pv4 subnetting
I pv4 subnetting
 
I pv4 multicast
I pv4 multicastI pv4 multicast
I pv4 multicast
 
I psec
I psecI psec
I psec
 
Ios zone based-firewall
Ios zone based-firewallIos zone based-firewall
Ios zone based-firewall
 
Ios i pv4_access_lists
Ios i pv4_access_listsIos i pv4_access_lists
Ios i pv4_access_lists
 

Ieee 802.1 x

  • 1. IEEE 802.1X packetlife.net 802.1X Header Terminology 1 1 2 Extensible Authentication Protocol (EAP) Version Type Length EAP A flexible authentication framework defined in RFC 3748 EAP Over LANs (EAPOL) EAP encapsulated by 802.1X for transport across LANs EAP Header Supplicant 1 1 2 The device (client) attached to an access link that requests Code Identifier Length Data authentication by the authenticator Authenticator EAP Flow Chart The device that controls the status of a link; typically a wired switch or wireless access point Authentication Supplicant Authenticator Server Authentication Server A backend server which authenticates the credentials provided by supplicants (for example, a RADIUS server) Guest VLAN Fallback VLAN for clients not 802.1X-capable Restricted VLAN Identity Request Fallback VLAN for clients which fail authentication 802.1X Packet Types EAP Codes Identity Response Access Request 0 EAP Packet 1 Request Challenge Request Access Challenge 1 EAPOL-Start 2 Response 2 EAPOL-Logoff 3 Success Challenge Response Access Request 3 EAPOL-Key 4 Failure 4 EAPOL-Encap-ASF-Alert EAP Req/Resp Types Success Access Accept Interface Defaults 1 Identity EAP RADIUS Max Auth Requests 2 2 Notification Configuration Reauthentication Off 3 Nak Quiet Period 60s 4 MD5 Challenge ! Define a RADIUS server Global Configuration radius-server host 10.0.0.100 Reauth Period 1hr 5 One Time Password radius-server key MyRadiusKey ! Configure 802.1X to authenticate via AAA Server Timeout 30s 6 Generic Token Card aaa new-model Supplicant Timeout 30s 254 Expanded Types aaa authentication dot1x default group radius ! Enable 802.1X authentication globally Tx Period 30s 255 Experimental dot1x system-auth-control Port-Control Options ! Static access mode Interface Configuration force-authorized switchport mode access ! Enable 802.1X authentication per port Port will always remain in authorized state (default) dot1x port-control auto force-unauthorized ! Configure host mode (single or multi) Always unauthorized; authentication attempts are ignored dot1x host-mode single-host ! Configure maximum authentication attempts auto dot1x max-reauth-req Supplicants must authenticate to gain access ! Enable periodic reauthentication dot1x reauthentication Troubleshooting ! Configure a guest VLAN dot1x guest-vlan 123 show dot1x [statistics] [interface <interface>] ! Configure a restricted VLAN dot1x test eapol-capable [interface <interface>] dot1x auth-fail vlan 456 dot1x auth-fail max-attempts 3 dot1x re-authenticate interface <interface> by Jeremy Stretch v2.0