Understanding RADIUS Snooper set radius-snooping port
26-4 RADIUS Snooping Configuration
Example
ThisexampleshowshowtosettheRStimeoutto30seconds:
Matrix(rw)->set radius-snooping timeout 30
set radius-snooping port
UsethiscommandtoenableRSonallorthespecifiedport(s).
Syntax
set radius-snooping port [enable | disable] [timeout seconds] [drop {enable |
disable}] [authallocated number] [port-string]
Parameters
Defaults
Ifnotimeoutvalueisspecified,theglobaltimeoutvaluespecifiedinthesetradius‐snooping
timeoutcommandisused.
Ifnoparametersarespecified,RADIUSsnoopingisenabledonallports.
Mode
Read‐write.
Usage
Ifthetimeouttimerexpires,theaffectedsessionisterminated.Iftimeoutissetto0,theglobal
timeoutisused.
Settheauthallocatedvalueequaltoorlessthantheconfiguredvalueforsetmultiauthport
numusers.Thisvalueisthemaximumnumberofusersperportforall
authenticationclients.
InsomecasesitmaybenecessarytodropRADIUStrafficinordertomaintainsessionconsistency
betweenthedistributiontierdeviceandtheedgeswitches.Packetsarealwaysdroppedfora
resourceissuesituation.Withdropenabled,frameswithaninvalidcallingstationIDarealso
dropped.
enable|
disable EnablesordisablesRSfunctionalityonthespecifiedport(s).Disabled
bydefault.
timeoutseconds SpecifiesthenumberofsecondsthefirmwarewaitsforaRADIUS
responseframeafteritsuccessfullysnoopsaRADIUSrequestframe.
Thetimeouttimerdefaultsto0seconds(unset).When0secondsis
configured,thefirmwareuses
thesystemleveltimeoutvalue.
drop{enable|
disable}
SetstheRADIUStrafficdropbehaviorforthisport.Disabledbydefault.
authallocatednumber SetsthenumberofallowedRSsessionsallowedonaperportbasis.
Defaultvalueis8,128,or256dependinguponthe systemlicensefor
thisdevice.
port‐string
EnablesRSforthespecifiedport(s).