Authentication, Association, Other related frames – H3C Technologies H3C MSR 50 User Manual
Page 5
1-4
g
Figure 1-4 Passive scannin
Authentication
To prevent illegal clients from accessing a network, authentication is needed between clients and ACs
or between clients and fat APs. There are two types of authentication:
z
Open system authentication
z
Shared key authentication
For details about the two types of authentication, refer to WLAN Security Configuration in the WLAN
Volume.
Association
A client that wants to access a wireless network via an AP must be associated with that AP. Once the
client chooses a compatible network with a specified SSID and authenticates to an AP, it sends an
association request frame to the AP. The AP sends an association response to the client and adds the
client’s information in its database. At a time, a client can associate with only one AP. An association
process is always initiated by the client, but not by the AP.
Other related frames
1) De-authentication
An AC or a fat AP sends a de-authentication frame to remove a client from the wireless system.
De-authentication can occur due to many reasons, such as:
z
Receiving an association/disassociation frame from a client which is unauthenticated.
z
Receiving a data frame from a client which is unauthenticated.
z
Receiving a PS-poll frame from a client which is unauthenticated.
z
The validity timer for a client expires and the port is not secured.
2) Dissociation
A client sends a dissociation frame to an AP to end the association between them. Dissociation can
occur due to many reasons, such as:
z
Receiving a data frame from a client which is authenticated and unassociated.
z
Receiving a PS-Poll frame from a client which is authenticated and unassociated.
A dissociation frame is either unicast or broadcast.
3) Re-association
When a client is roaming from one AP to another AP, it sends a re-association request to the new AP.
The AP relays this re-association request to the AC. The AC then informs the previous AP to delete the
client’s information from its database, informs the new AP to add the client’s information in its database
and conveys successful re-association information to the client.