03-20-2016 06:26 PM - edited 03-10-2019 11:36 PM
Hello,
I am confused with the process of EAP when I compare it between wired and wireless. As much as I understand in order for EAP to work in case of wired 802.1x authentication, the client has to have an IP address on it in advance. In other words EAP process can't start without the IP address on the wired client. For the same reason probably we allow DHCP traffic to pass in low impact mode.
But when it comes to wireless it looks like EAP process can work without an IP address being required on the wireless client. Is my understanding correct? If yes, how can EAP process progress without an IP address on the client because there could be a scenario that RADIUS/ISE server might be available to client over a layer 3 network for 802.1x authentication.
Thanks in advance for clarifying this confusion. Also I'd appreciate any link to a good document covering this concept.
Regards,
Qamber
Solved! Go to Solution.
03-26-2016 01:08 PM
EAPOL traffic between switch and host is not over IP and flows even before DHCP.
03-26-2016 01:08 PM
EAPOL traffic between switch and host is not over IP and flows even before DHCP.
03-29-2016 08:48 AM
Many thanks Peter for helping to clarify concept.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide