Specifications

RADIUS-Snooping Overview
June 03, 2011 Page 4 of 12
table.Bydefault,theRADIUSSnoopingflowtableisempty.Entriesareaddedtotheflowtable
baseduponanindexentry.Thefirstmatchingentryinthetableisusedforthecontinuationofthe
authenticationprocess.
WhenaninvestigatedRADIUSframetransitstheRSenabledportwithamatch
intheflowtable,
RSwilltrackthatRADIUSrequestandresponseexchangeandwillbuildaMultiAuthsessionfor
theenduser,baseduponwhatitfindsintheRADIUSresponseframes.
Setting the RADIUS-Snooping Timeout
AtimeoutisconfiguredtosetthenumberofsecondsthatthefirmwarewaitsforaRADIUS
responseframetobereturnedfromtheRADIUSserver,aftersuccessfullysnoopingaRADIUS
requestframefromtheclient.Ifnoresponseisseenbeforethetimeoutexpires,thesessionis
terminated.
RADIUS-Snooping Management
RADIUSSnoopingmanagementoptionsareavailableto:
•TerminateallRSsessionsoronaperportorMACaddressbasis
•ResetallRSconfigurationtoitsdefaultsettings
•ClearallRADIUSSnoopingflowtableentriesorperindexentry
•DisplayRSstatistics
RADIUS Session Attributes
TheRADIUSattributesdefiningthe sessionarereturnedintheRADIUSresponseframe.RADIUS
attributesareusedtoconfiguretheuseronthesystem.AttributesexplicitlysupportedbyRSthat
maybeincludedintheRADIUSresponseframeare:
•IdleTimeoutIfnoframesareseenfromthisMACaddress,
forthenumberofseconds
configured,thesessionwillbeterminated.
•SessionTimeoutThesessionisterminatedafterthenumberofsecondsconfigured.
•FilterID Definesthepolicyprofile(role)andCLImanagementprivilegelevel,justasit
wouldforanyotherlocalauthenticationagent.
•TunnelGroupIdSpecifies
theVLANIDforthissession.
Note: Numerous attributes may be supported by the RADIUS client for general RADIUS protocol
support. Such attributes are beyond the scope of this document. This RS implementation does not
interfere with normal RADIUS client attribute support. The list above indicates attributes actually
used by this RADIUS-Snooping application once authentication is successfully completed.