EasyManua.ls Logo

Enterasys Matrix DFE-Gold Series

Enterasys Matrix DFE-Gold Series
944 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Loading...
Enterasys Matrix DFE-Gold Series Configuration Guide 26-1
26
RADIUS Snooping Configuration
ThischapterdescribestheRADIUSSnoopingcommandsandhowtousethem.
Understanding RADIUS Snooper
RADIUSSnooper(RS)allowsanetworkmanagertomanagedownstreamconnections,whenthe
fullcomplementofEnterasys’SecureNetworkscapabilitiesisnotdeployedatthenetworkedge.
Thisallowsforthedeploymentoflessfeaturerichedgedevicestoperformbasicaccesscontrolat
thenetworkedge,whilestillprovidingcomplexuser
andservicebasedCoSprovisioning,
authorization,andusageauditingtothesession.
ManydownstreamdevicesauthenticatethelocalsessionwithaRADIUSserverthatresides
upstreamofthedistributiontierdevice.RADIUSrequestandresponseframesfromthesedevices
transitthedistributiontierdevice.TheinterceptionofthisRADIUStrafficallows
thedistribution
tierdevicetobuildanauthenticatedsessionfortheendstation,asthoughitwasdirectly
connected.SessionsdetectedbyRSfunctionidenticallytolocalauthenticatedsessions fromthe
perspectiveoftheEnterasysMultiAuthframework.
TheunencryptedtrafficofthedownstreamdevicespassesthroughthedevicerunningRS,
allowing
suchMultiAuthandSecureNetworkfeaturesassessiontimeout,idletimeout,filterID
attributesandVLANtunnelattributestobeappliedtothetraffic.
TheclientsendsaRADIUSAccessRequestframetotheRADIUSservertoinitiatethe
authenticationprocess.ThisrequestframecontainstheCallingStationIDattribute.TheCalling
StationID,containingtheMACaddress,iscapturedbytheRS.Thesessionisdefinedbythe
attributesreturnedbytheRADIUSserverintheAccessAcceptframe.Theidletimeoutand
sessiontimeoutdictatetheendofthesession,justasifthesessionwasdirectlyconnectedtothe
distributedtierdevicerunningRS.
TheRSflowtablecontainsflowsforeachvalidsessionforthissystem.TheclientIPaddressand
authenticatingRADIUSserverIP addressaremanuallyenteredintotheRADIUSflowtableonthe
RSenabledswitch.WhenaninvestigatedRADIUSframetransitstheRSenabledport
witha
matchintheflowtable,asessioniscreated.Thesessionbecomesactivewhenitseesaresponsefor
thesessionmatchfromtheRADIUSserver.
Aconfigurabletimerdeterminestheamountoftimethefirmwarewillwaitbeforeterminatinga
sessionbecausenoresponsewasseenfromthe
RADIUSserver.
DefaultandnetworkadministratorconfigurableRADIUSpacketdropsettingsexistbasedupon
resourceissuesandvalidationfailure.Packetdropforvalidationfailurescanbeconfiguredona
portbyportbasis.
ToconfigureRSonaswitch:
Note: An Enterasys Feature Guide document that contains a complete discussion on RADIUS
Snooping configuration exists at the following Enterasys web site: http://www.enterasys.com/
support/manuals/

Table of Contents

Related product manuals