EasyManua.ls Logo

Cisco Catalyst 2950 - RADIUS Operation

Cisco Catalyst 2950
376 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
6-25
Catalyst 2950 Desktop Switch Software Configuration Guide
78-11380-03
Chapter 6 Configuring the System
Controlling Switch Access with RADIUS
RADIUS is not suitable in these network security situations:
Multiprotocol access environments. RADIUS does not support AppleTalk Remote Access (ARA),
NetBIOS Frame Control Protocol (NBFCP), NetWare Asynchronous Services Interface (NASI), or
X.25 PAD connections.
Switch-to-switch or router-to-router situations. RADIUS does not provide two-way authentication.
RADIUS can be used to authenticate from one device to a non-Cisco device if the non-Cisco device
requires authentication.
Networks using a variety of services. RADIUS generally binds a user to one service model.
Figure 6-5 Typical AAA Network Configuration
RADIUS Operation
When a user attempts to log in and authenticate to a switch that is access controlled by a RADIUS server,
these events occur:
1. The user is prompted to enter a username and password.
2. The username and encrypted password are sent over the network to the RADIUS server.
3. The user receives one of these responses from the RADIUS server:
a. ACCEPTThe user is authenticated.
b. REJECTThe user is either not authenticated and is prompted to re-enter the username and
password, or access is denied.
c. CHALLENGEA challenge requires additional data from the user.
d. CHALLENGE PASSWORDA response requests the user to select a new password.
65520
RADIUS
server
RADIUS
server
TACACS+
server
TACACS+
server
R1
R2
T1
T2
Catalyst 2950 switch
Remote
PC
Workstation

Table of Contents

Other manuals for Cisco Catalyst 2950

Related product manuals