Specifications

June 03, 2011 Page 1 of 12
Configuring RADIUS-Snooping
Thischapterprovidesthefollowinginformationaboutconfiguringandmonitoring
RADIUSSnoopingonEnterasys
®
NSeries,SSeries
®
,andKSeriesmodularswitches.
What is RADIUS-Snooping?
RADIUSSnooping(RS)isoneoftheEnterasys
®
MultiAuthsuiteofauthenticationmethods.See
theConfiguringAuthenticationFeatureGuideforadetaileddiscussionoftheotherauthentication
methodssupportedbyEnterasysmodularswitches.RSresidesonthedistributiontierswitch,
allowingformanagementofanydirectlyconnectededgeswitchthatusestheRADIUSprotocolto
authenticateanetwork
endstation,butdoesnotsupportthefullcomplementoftheEnterasys
®
SecureNetworks™capabilities.
TheRADIUSclientedgeswitchinitiatesanauthenticationrequest,bysendingaRADIUSrequest
totheRADIUSserverthatresidesupstreamofthedistributiontierswitch.Byinvestigatingthe
RADIUSrequestframes,RScandeterminetheMACaddressoftheenduserdevicebeing
authenticated.Thenetwork
administratorcreatesauseraccountontheRADIUSserverforthe
enduserthatincludesanypolicy,dynamicVLANassignment,andotherRADIUSandRS
attributesforthisendstation.By investigatingtheRADIUSresponsefromtheRADIUSserver,RS
canbuildaMutiAu thsessionasthoughtheenduserwere
directlyconnectedtothe
distributiontierdevice.
SessionsdetectedbyRSfunctionidenticallytolocalauthenticatedsessionsfromtheperspectiveof
theEnterasysMultiAuthframework,withtheexceptionthatRScannotforceareauthentication
event;itcanonlytimeoutthesession.
For information about... Refer to page...
What is RADIUS-Snooping? 1
Why Would I Use RADIUS-Snooping in My Network? 2
How Can I Implement RADIUS-Snooping? 2
RADIUS-Snooping Overview 2
Configuring RADIUS-Snooping 6
RADIUS-Snooping Configuration Example 8
Terms and Definitions 10