PLANET GSW-1602SF User Manual

Page 111

Advertising
background image

User’s Manual of GSW-1602SF / GSW-2404SF

The above graph shows the network topology of the solution we are going to introduce. As illustrated, a group of clients is

trying to build a network with GSW-1602SF / GSW-2404SF in order to have access to both Internet and Intranet. With

802.1X authentication, each of these clients would have to be authenticated by RADIUS server. If the client is authorized,

GSW-1602SF / GSW-2404SF would be notified to open up a communication port to be used for the client. There are 2

Extensive Authentication Protocol (EAP) methods supported: (1) MD5 and (2) TLS.

MD5 authentication is simply a validation of existing user account and password that is stored in a database of RADIUS

server. Therefore, clients will be prompted for account/password validation to build the link. TLS authentication is a more

complicated authentication, which is using certificate that is issued by RADIUS server for authentication. TLS

authentication is a more secure authentication, since not only RADIUS server authenticates the client, but also the client

can validate RADIUS server by the certificate that it issues. The TLS authentication request from clients and reply by

Radius Server and GSW-1602SF / GSW-2404SF can be briefed as follows:

1. The client sends an EAP start message to Web Smart Gigabit Switch.

2. Web Smart Gigabit Switch replies with an EAP Request ID message.

3. The client sends its Network Access Identifier (NAI) – its user name – to Web Smart Gigabit Switch in an EAP

Respond message.

4. Web Smart Gigabit Switch forwards the NAI to the RADIUS server with a RADIUS Access Request message.

5. The RADIUS server responds to the client with its digital certificate.

6. The client validates the digital certificate, and replies its own digital certificate to the RADIUS server.

7. The RADIUS server validates client’s digital certificate.

8. The client and RADIUS server derive encryption keys.

9. The RADIUS server sends Web Smart Gigabit Switch a RADIUS ACCEPT message.

10. Web Smart Gigabit Switch sends the client an EAP Success message along with the broadcast key and key

length.

-105-

Advertising
This manual is related to the following products: