Discovering Extensible Authentication Protocol
Port-based network access control uses the physical access characteristics of IEEE 802 LAN infrastructures. These infrastructures leverage the Extensible Authentication Protocol (EAP) to carry arbitrary authentication information, not the authentication method itself.
EAP is an encapsulation protocol with no dependency on IP, and it can run over any link layer, including IEEE 802 media. EAP transports authentication information in the form of EAP payloads. EAP also establishes and manages the authentication connection, and it allows for authentication by encapsulating various types of authentication exchanges.
EAP over LANs (EAPOL) is the protocol in IEEE 802.1X. Figure 17-1 shows this framing format.
Figure 17-1 EAPOL Framing Format
Data
|
Protocol Version 1 Byte |
P |
acket Type 1 1 Byte |
Packet Length 2 Byte |
Packet Body N Byte |
|
Packet Type > |
' Packet Description |
|
EAP Packet (0) |
Both the Supplicant and the Authenticator Send this Packet It's Used During Authentication and Contains MD5 or TLS Information Required to Complete the Authentication Process |
|
EAPOL Start (1) |
Sent by Supplicant When It Starts Authentication Process |
|
EAPOL Logoff (2) |
Sent by Supplicant When It Wants to Terminate the 802.1X Session |
|
EAPOL Key (3) |
Sent by Switch to the Supplicant and Contains a Key Used During TLS Authentication |
EAP provides a means for authentication. The selection of an EAP method is potentially the most difficult and important decision regarding the deployment of port-based access control. Prevalent EAP types include the following:
• EAP-MD5. Uses message digest algorithm 5 (MD5)-based challenge response for authentication
• EAP-MSCHAPv2. Uses username/password MSCHAPv2 challenge-response authentication
• EAP-TLS. Uses x.509 v3 public-key infrastructure (PKI)-issued certificates and the Transport Layer Security (TLS) mechanism for strong mutual authentication
• PEAP. Combines server-side certificates with some other authentication, such as passwords, and tunnels other EAP types in an encrypted tunnel (TLS), much like web-based SSL
• EAP-FAST. Designed to not require certificates; tunnels other EAP types in an encrypted tunnel
EAP rose out of the need to reduce the complexity of relationships between systems and the increasing need for more elaborate and secure authentication methods. However, not every client device supports every EAP authentication method available and not every EAP server supports every method. In fact, most network devices are conduit for relaying EAP from a client to an EAP server.
Several factors drive the choice of an EAP method, such as the following:
• Support of EAP methods on clients and servers.
• Network security policy, such as mutual authentication.
• Backend directory infrastructure support. Not every identity store supports all EAP types.
The choice of an EAP type ultimately drives the components of a port-based network access control solution and everything else in an authentication infrastructure.
Continue reading here: Exploring IEEE 8021X
Was this article helpful?
Readers' Questions
-
teija8 months ago
- Reply