beautypg.com

Authentication, Association, Other related frames – H3C Technologies H3C MSR 50 User Manual

Page 5

background image

1-4

g

Figure 1-4 Passive scannin

Authentication

To prevent illegal clients from accessing a network, authentication is needed between clients and ACs

or between clients and fat APs. There are two types of authentication:

z

Open system authentication

z

Shared key authentication

For details about the two types of authentication, refer to WLAN Security Configuration in the WLAN

Volume.

Association

A client that wants to access a wireless network via an AP must be associated with that AP. Once the

client chooses a compatible network with a specified SSID and authenticates to an AP, it sends an

association request frame to the AP. The AP sends an association response to the client and adds the

client’s information in its database. At a time, a client can associate with only one AP. An association

process is always initiated by the client, but not by the AP.

Other related frames

1) De-authentication

An AC or a fat AP sends a de-authentication frame to remove a client from the wireless system.

De-authentication can occur due to many reasons, such as:

z

Receiving an association/disassociation frame from a client which is unauthenticated.

z

Receiving a data frame from a client which is unauthenticated.

z

Receiving a PS-poll frame from a client which is unauthenticated.

z

The validity timer for a client expires and the port is not secured.

2) Dissociation

A client sends a dissociation frame to an AP to end the association between them. Dissociation can

occur due to many reasons, such as:

z

Receiving a data frame from a client which is authenticated and unassociated.

z

Receiving a PS-Poll frame from a client which is authenticated and unassociated.

A dissociation frame is either unicast or broadcast.

3) Re-association

When a client is roaming from one AP to another AP, it sends a re-association request to the new AP.

The AP relays this re-association request to the AC. The AC then informs the previous AP to delete the

client’s information from its database, informs the new AP to add the client’s information in its database

and conveys successful re-association information to the client.