Specifications

Enterasys Matrix N Standalone (NSA) Series Configuration Guide 26-1
26
RADIUS Snooping Configuration
ThischapterdescribestheRADIUSSnoopingcommandsandhowtousethem.
Understanding RADIUS Snooper
RADIUSSnooper(RS)allowsanetworkmanagertomanagedownstreamconnections,whenthe
fullcomplementofEnterasys’SecureNetworkscapabilitiesisnotdeployedatthenetworkedge.
Thisallowsforthedeploymentoflessfeaturerichedgedevicestoperformbasicaccesscontrolat
thenetworkedge,whilestillprovidingcomplexuser
andservicebasedCoSprovisioning,
authorization,andusageauditingtothesession.
ManydownstreamdevicesauthenticatethelocalsessionwithaRADIUSserverthatresides
upstreamofthedistributiontierdevice.RADIUSrequestandresponseframesfromthesedevices
transitthedistributiontierdevice.TheinterceptionofthisRADIUStrafficallows
thedistribution
tierdevicetobuildanauthenticatedsessionfortheendstation,asthoughitwasdirectly
connected.SessionsdetectedbyRSfunctionidenticallytolocalauthenticatedsessions fromthe
perspectiveoftheEnterasysMultiAuthframework.
TheunencryptedtrafficofthedownstreamdevicespassesthroughthedevicerunningRS,
allowing
suchMultiAuthandSecureNetworkfeaturesassessiontimeout,idletimeout,filterID
attributesandVLANtunnelattributestobeappliedtothetraffic.
TheclientsendsaRADIUSAccessRequestframetotheRADIUSservertoinitiatethe
authenticationprocess.ThisrequestframecontainstheCallingStationIDattribute.TheCalling
StationID,containingtheMACaddress,iscapturedbytheRS.Thesessionisdefinedbythe
attributesreturnedbytheRADIUSserverintheAccessAcceptframe.Theidletimeoutand
sessiontimeoutdictatetheendofthesession,justasifthesessionwasdirectlyconnectedtothe
distributedtierdevicerunningRS.
TheRSflowtablecontainsflowsforeachvalidsessionforthissystem.TheclientIPaddressand
authenticatingRADIUSserverIP addressaremanuallyenteredintotheRADIUSflowtableonthe
RSenabledswitch.WhenaninvestigatedRADIUSframetransitstheRSenabledport
witha
matchintheflowtable,asessioniscreated.Thesessionbecomesactivewhenitseesaresponsefor
thesessionmatchfromtheRADIUSserver.
Aconfigurabletimerdeterminestheamountoftimethefirmwarewillwaitbeforeterminatinga
sessionbecausenoresponsewasseenfromthe
RADIUSserver.
DefaultandnetworkadministratorconfigurableRADIUSpacketdropsettingsexistbasedupon
resourceissuesandvalidationfailure.Packetdropforvalidationfailurescanbeconfiguredona
portbyportbasis.
ToconfigureRSonaswitch:
Note: An Enterasys Feature Guide document that contains a complete discussion on RADIUS
Snooping configuration exists at the following Enterasys web site: http://www.enterasys.com/
support/manuals/