Discovering Extensible Authentication Protocol

Port-based network access control uses the physical access characteristics of IEEE 802 LAN infrastructures. These infrastructures leverage the Extensible Authentication Protocol (EAP) to carry arbitrary authentication information, not the authentication method itself.

EAP is an encapsulation protocol with no dependency on IP, and it can run over any link layer, including IEEE 802 media. EAP transports authentication information in the form of EAP payloads. EAP also establishes and manages the authentication connection, and it allows for authentication by encapsulating various types of authentication exchanges.

EAP over LANs (EAPOL) is the protocol in IEEE 802.1X. Figure 17-1 shows this framing format.

Figure 17-1 EAPOL Framing Format

Data

Protocol Version 1 Byte

P

acket Type 1 1 Byte

Packet Length 2 Byte

Packet Body N Byte

Packet Type >

' Packet Description

EAP Packet (0)

Both the Supplicant and the Authenticator Send this Packet

It's Used During Authentication and Contains MD5 or TLS Information Required to Complete the Authentication Process

EAPOL Start (1)

Sent by Supplicant When It Starts Authentication Process

EAPOL Logoff (2)

Sent by Supplicant When It Wants to Terminate the 802.1X Session

EAPOL Key (3)

Sent by Switch to the Supplicant and Contains a Key Used During TLS Authentication

EAP provides a means for authentication. The selection of an EAP method is potentially the most difficult and important decision regarding the deployment of port-based access control. Prevalent EAP types include the following:

• EAP-MD5. Uses message digest algorithm 5 (MD5)-based challenge response for authentication

• EAP-MSCHAPv2. Uses username/password MSCHAPv2 challenge-response authentication

• EAP-TLS. Uses x.509 v3 public-key infrastructure (PKI)-issued certificates and the Transport Layer Security (TLS) mechanism for strong mutual authentication

• PEAP. Combines server-side certificates with some other authentication, such as passwords, and tunnels other EAP types in an encrypted tunnel (TLS), much like web-based SSL

• EAP-FAST. Designed to not require certificates; tunnels other EAP types in an encrypted tunnel

EAP rose out of the need to reduce the complexity of relationships between systems and the increasing need for more elaborate and secure authentication methods. However, not every client device supports every EAP authentication method available and not every EAP server supports every method. In fact, most network devices are conduit for relaying EAP from a client to an EAP server.

Several factors drive the choice of an EAP method, such as the following:

• Support of EAP methods on clients and servers.

• Network security policy, such as mutual authentication.

• Backend directory infrastructure support. Not every identity store supports all EAP types.

The choice of an EAP type ultimately drives the components of a port-based network access control solution and everything else in an authentication infrastructure.

Continue reading here: Exploring IEEE 8021X

Was this article helpful?

0 0

Readers' Questions

  • teija
    Which of the following is the most secure form of ieee 802.1x authentication?
    8 months ago
  • The most secure form of IEEE 802.1x authentication is known as Extensible Authentication Protocol - Transport Layer Security (EAP-TLS), which uses public key encryption and digital certificates for authentication. It is the most secure form of 802.1x authentication because it provides additional security features such as mutual authentication, session encryption and integrity protection.