Download presentation
Presentation is loading. Please wait.
Published byChristian Murphy Modified over 6 years ago
1
Informing AAA about what lower layer protocol is carrying EAP
Nov 2004 at IETF-61
2
The Problem The AAA (EAP) server receives two authentication requests with no knowledge of which service originated it Home Network Access Network AAA server Client VPN gateway AAA protocol is Diameter or RADIUS VPN gateway uses IKEv2 in EAP mode
3
The Solution Lower layer: 802.1X Lower layer: IKEv2
The EAP lower layer attribute indicates the EAP server the service that originated the authentication Lower layer: 802.1X Home Network Access Network AAA server Client VPN gateway Lower layer: IKEv2 The EAP server can take proper decision according to the EAP lla (authorize, reject, etc.)
4
The Alternatives New values for NAS-Port-Type or Service-Type
A standalone attribute (draft-mariblanca) A combination of NAS-Port-Type and something else NAS-Port-Type = /PANA/Virtual If Virtual, then we describe the specific protocol using either (a) RFC 2868 Tunnel-Type and Tunnel-Medium-Type (b) A new attribute NAS-Virtual-Port-Type Values: IKEv2, … Does the mandatory tunneling and incoming virtual protocol usage conflict?
Similar presentations
© 2025 SlidePlayer.com. Inc.
All rights reserved.