ÇÖȨͶËß
¶©ÔÄ
¾À´í
¼ÓÈë×ÔýÌå

ÍøÂç²âÊÔ¼¼ÊõÖ®8021.XÔ­Àí

Ò»¡¢ÒÔÌ«ÍøÓŵãȱµã

1£®ÒÔÌ«ÍøÓŵã

(1)¼´²å¼´ÓÃ,¼òµ¥¿ì½Ý

(2)ÈκÎһ̨µçÄÔÖ»Òª½ÓÈëÍøÂç±ãÓзÃÎÊÍøÂç×ÊÔ´µÄȨÏÞ

2£®ÒÔÌ«ÍøÈ±µã

(1)ȱ·¦°²È«ÈÏÖ¤»úÖÆ(¶þ²ã)

(2)µçÄÔ½Óµ½½»»»»úÉϾÍÄÜ·ÃÎÊÍøÂç

(3)°²È«ÐԵò»µ½±£ÕÏ

image.png

¶þ¡¢¶þ²ãÍøÂ簲ȫ¼¼Êõ

1£®ÔÚÓû§½ÓÈëÍøÂç֮ǰ½øÐÐÈÏÖ¤

2£®ÈÏ֤ͨ¹ý

(1)½»»»»ú¶Ë¿Ú´ò¿ª

(2)·ÃÎʶþ²ã¾ÖÓòÍø

3£®ÈÏÖ¤²»Í¨¹ý

(1)½»»»»ú¶Ë¿Ú¹Ø±Õ

(2)²»ÄÜ·ÃÎʶþ²ã¾ÖÓòÍø

image.png

Èý¡¢802£®1Xµ®Éú

1£®IEEE 802£®1X

(1)Port-Based Networks Access Control

(2)»ùÓڶ˿ڵÄÍøÂç½ÓÈë¿ØÖÆ

2£®ÆðÔ´ÓÚÎÞÏß±ê×¼802£®11ЭÒé

(1)×î³õÊÇΪ½â¾öÎÞÏß¾ÖÓòÍøµÄÓû§½ÓÈëÈÏÖ¤ÎÊÌâ

(2)¶Ô¾ÖÓòÍø¾ßÓÐÆÕÊÊÐÔ,ÒÆÖ²µ½ÓÐÏßÁìÓò

3£®Õýʽ±ê×¼

(1)IEEE 802ίԱ»áÖÆ¶¨µÄLAN±ê×¼

(2)2001Äê6Ô±ê×¼»¯

4£®DOT1x vs 802£®1x

(1)DOT1x = 802£®1x

(2)¡°£®¡± Ó¢ÎÄÊÇDOT

image.png

ËÄ¡¢802£®1XÈý¸ö½ÇÉ«

1£®Supplicant

(1)¿Í»§¶Ë

(2)Winow¡¢Linux¡¢MAC¡¢µÚÈý·½¿Í»§¶Ë

(3)Ö§³ÖEAPoLÈÏÖ¤

2£®Authenticator

(1)ÈÏ֤ϵͳ

(2)½»»»»ú

3£®Authentication Server

(1)ÈÏÖ¤·þÎñÆ÷

(2)Radius·þÎñÆ÷

(3)˼¿ÆACS¡¢»ªÎªPolicy Center¡¢Freeradius

image.png

Îå¡¢802£®1XÈÏÖ¤¹ý³Ì

1£®ÈÏÖ¤·¢ÉúµØµã

(1)¿Í»§¶Ë<--->·þÎñÆ÷

(2)ÈÏÖ¤ÔÚ¿Í»§¶ËºÍ·þÎñÆ÷Ö®¼ä½øÐÐ

2£®ÈÏ֤ϵͳ

(1)×÷Ϊ´úÀí

(2)½«EAPÈÏÖ¤´ÓÒÔÌ«Íø×ªÎªRadius¸ñʽ

(3)¸ÐÖªÈÏÖ¤¹ý³Ì

(4)²»¸ÐÖªÈÏÖ¤ÄÚÈÝ(½»»»ÐÅÏ¢)

image.png

Áù¡¢802£®1XÈÏÖ¤½á¹û

1£®ÈÏÖ¤³É¹¦

(1)ÈÏ֤ϵͳ´ò¿ª¶Ë¿Ú

(2)¶Ë¿Ú״̬±äΪAuthenticated

(3)½»»»»úת·¢¿Í»§¶Ë·¢Ëͱ¨ÎÄ

2£®ÈÏ֤ʧ°Ü

(1)ÈÏ֤ϵͳ¹Ø±Õ¶Ë¿Ú

(2)¶Ë¿Ú״̬ΪUnauthenticated

(3)½»»»»ú²»×ª·¢¿Í»§¶Ë·¢Ëͱ¨ÎÄ

image.png

Æß¡¢EAP¼ò½é

1£®802£®1XµÄºËÐÄÊÇEAP

(1)ÈÏÖ¤·¢ÉúÔÚ¿Í»§¶ËºÍÈÏÖ¤·þÎñÆ÷Ö®¼ä

(2)ÈÏ֤ϵͳ͸´«EAP±¨ÎÄ

2£®EAP

(1)Extensible Authentication Protocol

(2)¿ÉÀ©Õ¹ÈÏ֤ЭÒé

(3)RFC5247

image.png

°Ë¡¢EAPÊÇ¿ò¼Ü

1£®EAPÊÇÒ»¸öÈÏÖ¤¿ò¼Ü

(1)²»ÊǾßÌåµÄÈÏÖ¤»úÖÆ

(2)ÌṩЭÉÌ ¡°EAP·½·¨¡±µÄ¹¦ÄÜ

2£®EAP·½·¨

(1)RFC5247

(2)´óÔ¼40ÖÖ

(3)EAP-MD5, EAP-OTP, EAP-GTC, EAP-TLS, EAP-SIM

image.png

¾Å¡¢EAP·½·¨·ÖÀà:Tunneled EAP

1£®Tunneled EAP

(1)ÔÚ¿Í»§¶ËºÍ·þÎñÆ÷Ö®¼ä, ÏȽ¨Á¢°²È«ËíµÀ

(2)ÔÚ°²È«ËíµÀÀï, ʹÓà MD5¡¢GTC¡¢MSCHAP

2£®µäÐÍ´ú±í

(1)PEAP¡¢EAP-FAST¡¢TTLS

image.png

Ê®¡¢EAPoL

1£®EAPOL

(1)EAP over LAN

(2)»ùÓÚ¾ÖÓòÍøµÄÀ©Õ¹ÈÏ֤ЭÒé

(3)¶¨ÒåEAPÔÚÒÔÌ«ÍøÉϵĴ«Êä¸ñʽ

2£®ÒÔÌ«Íø·â×°

(1)Ä¿±êMACµØÖ·ÊÇ01-80-c2-00-00-03

image.png

ʮһ¡¢EAPoLÈÏ֤ȫ¹ý³Ì

1£®EAP»á»°ËĽ׶Î

(1)Session initiation

(2)Session authentication

(3)Session authorization

(4)Session accounting

image.png

ÉùÃ÷£º±¾ÎÄÓÉÈëפά¿ÆºÅµÄ×÷Õß׫д£¬¹Ûµã½ö´ú±í×÷Õß±¾ÈË£¬²»´ú±íOFweekÁ¢³¡¡£ÈçÓÐÇÖȨ»òÆäËûÎÊÌ⣬ÇëÁªÏµ¾Ù±¨¡£

·¢±íÆÀÂÛ

¹² 0ÌõÆÀÂÛ£¬ 0È˲ÎÓë

ÇëÊäÈëÆÀÂÛÄÚÈÝ...

ÇëÊäÈëÆÀÂÛ/ÆÀÂÛ³¤¶È6~500¸ö×Ö

ÄúÌá½»µÄÆÀÂÛ¹ýÓÚÆµ·±£¬ÇëÊäÈëÑéÖ¤Âë¼ÌÐø

ÔÝÎÞÆÀÂÛ

ÔÝÎÞÆÀÂÛ

¹âͨѶ ÁÔͷְλ ¸ü¶à
    ÎÄÕ¾À´í
    x
    *ÎÄ×Ö±êÌ⣺
    *¾À´íÄÚÈÝ£º
    ÁªÏµÓÊÏ䣺
    *Ñé Ö¤ Â룺

    ÔÁ¹«Íø°²±¸ 44030502002758ºÅ