Specifications
Why Would I Use RADIUS-Snooping in My Network?
June 03, 2011 Page 2 of 12
Why Would I Use RADIUS-Snooping in My Network?
RADIUS‐SnoopingallowstheEnterasysdistribution‐tierswitchtoidentifyRADIUSexchanges
betweendevicesconnectedtoedgeswitchesandapplypolicytothosedevicesevenwhenthe
edgeswitchisfromanothervendoranddoesnotsupportpolicy.RADIUS‐Snoopingprovides,but
isnotlimitedto,thefollowingfunctionalities:
•RFC3580
DynamicVLANassignment
• Authenticationmodessupport
•Idleandsessiontimeoutssupport
•Multi‐userauthenticationonaport
•Multi‐authenticationmethodsupport
WithRS‐enabledonthedistribution‐tierswitch,theseSecureNetworkscapabilitiescanbe
configuredbythenetworkadministratoronanend‐userbasis.
How Can I Implement RADIUS-Snooping?
RSrequiresthatunencryptedRADIUSrequestframes,fromtheedgeswitch,transitthe
distribution‐tierswitch,beforeproceedingtotheup‐streamRADIUSserverforvalidation.
ToconfigureRSonadistribution‐tierswitch:
•SettheglobalMultiAuthmodetomulti
•SettheMultiAuthportmodetoauth‐optforallports
thatarepartoftheRSconfiguration
• GloballyenableRSonthedistribution‐tierswitch
•EnableRSonallportsoverwhichRADIUSrequestandresponseframeswilltransit
• OptionallychangetheperiodRSwillwaitforaRADIUSresponseframefromtheserver
• PopulatetheRADIUS ‐SnoopingflowtablewithRS
clientandRADIUSservercombinations
RADIUS-Snooping Overview
ThissectionprovidesanoverviewofRADIUS‐Snoopingconfigurationandmanagement.
Note: A router cannot reside between the RADIUS client and the distribution-tier switch enabled for
RS. The presence of a router would modify the calling-station ID of the RADIUS request frame that
RS depends upon to learn the MAC address of the end-station for this session.
Note: RADIUS-Snooping is currently only supported on Enterasys modular switch products.
A minimum of 256 MB of memory is required on all DFE modules in the switch, in order to enable
RADIUS-Snooping. See the SDRAM field of the show system hardware command to display the
amount of memory installed on a module. Module memory can be upgraded to 256 MB using the
DFE-256MB-UGK memory kit.