Specifications

Why Would I Use RADIUS-Snooping in My Network?
June 03, 2011 Page 2 of 12
Why Would I Use RADIUS-Snooping in My Network?
RADIUSSnoopingallowstheEnterasysdistributiontierswitchtoidentifyRADIUSexchanges
betweendevicesconnectedtoedgeswitchesandapplypolicytothosedevicesevenwhenthe
edgeswitchisfromanothervendoranddoesnotsupportpolicy.RADIUSSnoopingprovides,but
isnotlimitedto,thefollowingfunctionalities:
•RFC3580
DynamicVLANassignment
Authenticationmodessupport
•Idleandsessiontimeoutssupport
•Multiuserauthenticationonaport
•Multiauthenticationmethodsupport
WithRSenabledonthedistributiontierswitch,theseSecureNetworkscapabilitiescanbe
configuredbythenetworkadministratoronanenduserbasis.
How Can I Implement RADIUS-Snooping?
RSrequiresthatunencryptedRADIUSrequestframes,fromtheedgeswitch,transitthe
distributiontierswitch,beforeproceedingtotheupstreamRADIUSserverforvalidation.
ToconfigureRSonadistributiontierswitch:
•SettheglobalMultiAuthmodetomulti
•SettheMultiAuthportmodetoauthoptforallports
thatarepartoftheRSconfiguration
GloballyenableRSonthedistributiontierswitch
•EnableRSonallportsoverwhichRADIUSrequestandresponseframeswilltransit
OptionallychangetheperiodRSwillwaitforaRADIUSresponseframefromtheserver
PopulatetheRADIUS SnoopingflowtablewithRS
clientandRADIUSservercombinations
RADIUS-Snooping Overview
ThissectionprovidesanoverviewofRADIUSSnoopingconfigurationandmanagement.
Note: A router cannot reside between the RADIUS client and the distribution-tier switch enabled for
RS. The presence of a router would modify the calling-station ID of the RADIUS request frame that
RS depends upon to learn the MAC address of the end-station for this session.
Note: RADIUS-Snooping is currently only supported on Enterasys modular switch products.
A minimum of 256 MB of memory is required on all DFE modules in the switch, in order to enable
RADIUS-Snooping. See the SDRAM field of the show system hardware command to display the
amount of memory installed on a module. Module memory can be upgraded to 256 MB using the
DFE-256MB-UGK memory kit.