100 CN4093 Application Guide for N/OS 8.4
RADIUS Authentication and Authorization
EnterpriseNOSsupportstheRADIUS(RemoteAuthenticationDial‐inUser
Service)methodtoauthenticateandauthorizeremoteadministratorsfor
managingtheswitch.Thismethodisbasedonaclient/servermodel.TheRemote
AccessServer(RAS)—theswitch—isaclienttotheback‐enddatabaseserver.A
remoteuser(theremoteadministrator)interacts
onlywiththeRAS,notthe
back‐endserveranddatabase.
RADIUSauthenticationconsistsofthefollowingcomponents:
AprotocolwithaframeformatthatutilizesUDPoverIP(basedonRFC2138
and2866)
Acentralizedserverthatstoresalltheuserauthorizationinformation
Aclient,inthiscase,theswitch
TheCN4093—actingastheRADIUSclient—communicatestotheRADIUSserver
toauthenticateandauthorizearemote administratorusingtheprotocoldefinitions
specifiedinRFC2138and2866.TransactionsbetweentheclientandtheRADIUS
serverareauthenticatedusingasharedkeythatisnot
sentoverthenetwork.In
addition,theremoteadministratorpasswordsaresentencryptedbetweenthe
RADIUSclient(theswitch)andtheback‐endRADIUSserver.
How RADIUS Authentication Works
1. Remoteadministratorconnectstotheswitchandprovidesusernameand
password.
2. UsingAuthentication/Authorizationprotocol,theswitchsendsrequestto
authenticationserver.
3. AuthenticationservercheckstherequestagainsttheuserIDdatabase.
4. UsingRADIUSprotocol,theauthenticationserverinstructstheswitchtograntor
denyadministrativeaccess.