Specifications
June 03, 2011 Page 1 of 12
Configuring RADIUS-Snooping
Thischapterprovidesthefollowinginformationaboutconfiguringandmonitoring
RADIUS‐SnoopingonEnterasys
®
N‐Series,S‐Series
®
,andK‐Seriesmodularswitches.
What is RADIUS-Snooping?
RADIUS‐Snooping(RS)isoneoftheEnterasys
®
MultiAuthsuiteofauthenticationmethods.See
theConfiguringAuthenticationFeatureGuideforadetaileddiscussionoftheotherauthentication
methodssupportedbyEnterasysmodularswitches.RSresidesonthedistribution‐tierswitch,
allowingformanagementofanydirectlyconnectededgeswitchthatusestheRADIUSprotocolto
authenticateanetwork
end‐station,butdoesnotsupportthefullcomplementoftheEnterasys
®
SecureNetworks™capabilities.
TheRADIUSclientedge‐switchinitiatesanauthenticationrequest,bysendingaRADIUSrequest
totheRADIUSserverthatresidesupstreamofthedistribution‐tierswitch.Byinvestigatingthe
RADIUSrequestframes,RScandeterminetheMACaddressoftheend‐userdevicebeing
authenticated.Thenetwork
administratorcreatesauseraccountontheRADIUSserverforthe
end‐userthatincludesanypolicy,dynamicVLANassignment,andotherRADIUSandRS
attributesforthisend‐station.By investigatingtheRADIUSresponsefromtheRADIUSserver,RS
canbuildaMutiAu thsessionasthoughtheend‐userwere
directlyconnectedtothe
distribution‐tierdevice.
SessionsdetectedbyRSfunctionidenticallytolocalauthenticatedsessionsfromtheperspectiveof
theEnterasysMultiAuthframework,withtheexceptionthatRScannotforceareauthentication
event;itcanonlytimeoutthesession.
For information about... Refer to page...
What is RADIUS-Snooping? 1
Why Would I Use RADIUS-Snooping in My Network? 2
How Can I Implement RADIUS-Snooping? 2
RADIUS-Snooping Overview 2
Configuring RADIUS-Snooping 6
RADIUS-Snooping Configuration Example 8
Terms and Definitions 10