xi
Cached Reauthentication . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-28
Timing Considerations . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-29
Using SNMP To View and Configure
Switch Authentication Features . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-32
Changing and Viewing the SNMP Access Configuration . . . . . . . . . . 6-33
Local Authentication Process . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-36
Controlling WebAgent Access . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-37
Commands Authorization . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-38
Enabling Authorization . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-39
Displaying Authorization Information . . . . . . . . . . . . . . . . . . . . . . . . . 6-40
Configuring Commands Authorization on a RADIUS Server . . . . . . 6-40
Using Vendor Specific Attributes (VSAs) . . . . . . . . . . . . . . . . . . . 6-40
Example Configuration on Cisco Secure ACS for MS Windows 6-43
Example Configuration Using FreeRADIUS . . . . . . . . . . . . . . . . . 6-46
VLAN Assignment in an Authentication Session . . . . . . . . . . . . . . . . 6-47
Tagged and Untagged VLAN Attributes . . . . . . . . . . . . . . . . . . . . . . . . 6-47
Additional RADIUS Attributes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-48
MAC-Based VLANs . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-51
Accounting Services . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-52
Accounting Service Types . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-52
Operating Rules for RADIUS Accounting . . . . . . . . . . . . . . . . . . . . . . 6-53
Acct-Session-ID Options in a Management Session . . . . . . . . . . . . . . 6-54
Unique Acct-Session-ID Operation . . . . . . . . . . . . . . . . . . . . . . . . 6-54
Common Acct-Session-ID Operation . . . . . . . . . . . . . . . . . . . . . . . 6-56
Configuring RADIUS Accounting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-57
Steps for Configuring RADIUS Accounting . . . . . . . . . . . . . . . . . . . . . 6-57
1. Configure the Switch To Access a RADIUS Server . . . . . . . . . 6-58
2. (Optional) Reconfigure the Acct-Session-ID Operation . . . . . 6-60
3. Configure Accounting Types and the Controls for Sending
Reports to the RADIUS Server . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-61
4. (Optional) Configure Session Blocking and Interim
Updating Options . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-66
Viewing RADIUS Statistics . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-67
General RADIUS Statistics . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 6-67