Specifications

RADIUS-Snooping Overview
June 03, 2011 Page 3 of 12
RADIUS-Snooping Configuration
MultiAuth Configuration
MultiAuthmust beenablediftheRADIUSSnoopingconfigurationinvolvestheauthenticationof
morethanasingleuseronaport.Therearetwoaspectstomultiauthenticationina
RADIUSSnoopingconfiguration:
•TheglobalMultiAuthmodemustbechangedfromthedefaultmodeofstricttomulti,in
ordertoauthenticate
multipledownstreamusers.
•TheMultiAuthportmodemustbesettoauthoptforbothupstream(totheRADIUSserver)
anddownstream(totheauthenticatingswitch)ports.Setting globalMultiAuthtomultisets
thedefaultportvaluefromauthopttoforceauth.Resetthemodefortheaffectedports
to
authopt.
SeetheConfiguringUserAuthenticationfeatureguideathttps://extranet.enterasys.com/downloads/
foracompletediscussiononMultiAuthconfiguration.
Enabling RADIUS-Snooping
RSisenabledgloballyonthedistributiontierswitch.Itisalsoenabledonthedistributiontier
switchportsdirectlyattachedtotheedgeswitchthattheRADIUSrequestframestransit,fromthe
edgeswitchtotheRADIUSserver,aswellastheportstheresponseframestransit,fromthe
RADIUS
serverbacktotheedgeswitch.
Configuring Enabled Port Settings
ThenumberofsecondsthefirmwarewaitsforaRADIUSresponseafteritsuccessfullysnoopsa
RADIUSrequestcanbesetperport.Ifyoudonotsetthistimeoutattheportlevel,thesystem
levelsettingisused.
InsomecasesitmaybenecessarytodropRADIUStraffic
betweenthedistributiontierdeviceand
theedgeswitches.Youcanenable ordisablepacketdroponaperportbasis.Packetsarealways
droppedforaresourceissuesituation.RSisnotcapableofforcingareauthentica tioneventshould
itbeunabletoinvestigateaRADIUS requestexchange.Droppinga
RADIUSrequestpacketdueto
resourceexhaustion,inmostcases,willcausetheedgedevicetoretryaRADIUSrequest,
providinganotheropportunitytosnooptheRADIUSexchange.Frameswithaninvalidformatfor
thecallingstationIDareonlydroppedwhendropisenabled.Inthecaseofdropping
frameswith
aninvalidformat,authenticationwillnottakeplaceforthisenduser.
TheauthallocatedvaluespecifiesthemaximumnumberofRSusersperport.Youcanconfigure
thisnumberofallowedRSusersonaperportbasis.Thedefaultvaluedependsuponthesystem
licenseforthisdevice.
Youshouldsetthisauthallocatedvalueequaltoorlessthantheconfigured
valueforthesetmultiauthportnumuserscommand.Thisvalueisthemaximumnumberofusers
perportforallauthenticationclients.Typically ,authallocatedandmultiauthportnumusersare
settothesamevalue.
Populating the RADIUS-Snooping Flow Table
TheRADIUSSnoopingflowtableisafilterthatdetermineswhichRADIUSserverandclient
combinationswillbesnooped.Ifthesecretisconfigured,theresponseframesarecheckedfor
validMD5checksum,inordertovalidatethesender.
TheRSflowtablecontainsRADIUSserverandcliententriesforeach
RADIUSserverandclient
combinationforwhichRSwillbeusedonthissystem.TheRADIUSclientIPaddressand
authenticatingRADIUSserverIPaddressaremanuallyenteredintotheRADIUSSnoopingflow