Specifications
RADIUS-Snooping Overview
June 03, 2011 Page 3 of 12
RADIUS-Snooping Configuration
MultiAuth Configuration
MultiAuthmust beenablediftheRADIUS‐Snoopingconfigurationinvolvestheauthenticationof
morethanasingleuseronaport.Therearetwoaspectstomultiauthenticationina
RADIUS‐Snoopingconfiguration:
•TheglobalMultiAuthmodemustbechangedfromthedefaultmodeofstricttomulti,in
ordertoauthenticate
multipledownstreamusers.
•TheMultiAuthportmodemustbesettoauth‐optforbothupstream(totheRADIUSserver)
anddownstream(totheauthenticatingswitch)ports.Setting globalMultiAuthtomultisets
thedefaultportvaluefromauth‐opttoforce‐auth.Resetthemodefortheaffectedports
to
auth‐opt.
SeetheConfiguringUserAuthenticationfeatureguideathttps://extranet.enterasys.com/downloads/
foracompletediscussiononMultiAuthconfiguration.
Enabling RADIUS-Snooping
RSisenabledgloballyonthedistribution‐tierswitch.Itisalsoenabledonthedistribution‐tier
switchportsdirectlyattachedtotheedgeswitchthattheRADIUSrequestframestransit,fromthe
edgeswitchtotheRADIUSserver,aswellastheportstheresponseframestransit,fromthe
RADIUS
serverbacktotheedgeswitch.
Configuring Enabled Port Settings
ThenumberofsecondsthefirmwarewaitsforaRADIUSresponseafteritsuccessfullysnoopsa
RADIUSrequestcanbesetper‐port.Ifyoudonotsetthistimeoutattheportlevel,thesystem
levelsettingisused.
InsomecasesitmaybenecessarytodropRADIUStraffic
betweenthedistributiontierdeviceand
theedgeswitches.Youcanenable ordisablepacketdroponaperportbasis.Packetsarealways
droppedforaresourceissuesituation.RSisnotcapableofforcingareauthentica tioneventshould
itbeunabletoinvestigateaRADIUS requestexchange.Droppinga
RADIUSrequestpacketdueto
resourceexhaustion,inmostcases,willcausetheedgedevicetoretryaRADIUSrequest,
providinganotheropportunitytosnooptheRADIUSexchange.Frameswithaninvalidformatfor
thecallingstationIDareonlydroppedwhendropisenabled.Inthecaseofdropping
frameswith
aninvalidformat,authenticationwillnottakeplaceforthisend‐user.
TheauthallocatedvaluespecifiesthemaximumnumberofRSusersperport.Youcanconfigure
thisnumberofallowedRSusersonaperportbasis.Thedefaultvaluedependsuponthesystem
licenseforthisdevice.
Youshouldsetthisauthallocatedvalueequaltoorlessthantheconfigured
valueforthesetmultiauthportnumuserscommand.Thisvalueisthemaximumnumberofusers
perportforallauthenticationclients.Typically ,authallocatedandmultiauthportnumusersare
settothesamevalue.
Populating the RADIUS-Snooping Flow Table
TheRADIUS‐SnoopingflowtableisafilterthatdetermineswhichRADIUSserverandclient
combinationswillbesnooped.Ifthesecretisconfigured,theresponseframesarecheckedfor
validMD5checksum,inordertovalidatethesender.
TheRSflowtablecontainsRADIUSserverandcliententriesforeach
RADIUSserverandclient
combinationforwhichRSwillbeusedonthissystem.TheRADIUSclientIPaddressand
authenticatingRADIUSserverIPaddressaremanuallyenteredintotheRADIUS‐Snoopingflow