Specifications
RADIUS-Snooping Overview
June 03, 2011 Page 4 of 12
table.Bydefault,theRADIUS‐Snoopingflowtableisempty.Entriesareaddedtotheflowtable
baseduponanindexentry.Thefirstmatchingentryinthetableisusedforthecontinuationofthe
authenticationprocess.
WhenaninvestigatedRADIUSframetransitstheRS‐enabledportwithamatch
intheflowtable,
RSwilltrackthatRADIUSrequestandresponseexchangeandwillbuildaMultiAuthsessionfor
theend‐user,baseduponwhatitfindsintheRADIUSresponseframes.
Setting the RADIUS-Snooping Timeout
AtimeoutisconfiguredtosetthenumberofsecondsthatthefirmwarewaitsforaRADIUS
responseframetobereturnedfromtheRADIUSserver,aftersuccessfullysnoopingaRADIUS
requestframefromtheclient.Ifnoresponseisseenbeforethetimeoutexpires,thesessionis
terminated.
RADIUS-Snooping Management
RADIUS‐Snoopingmanagementoptionsareavailableto:
•TerminateallRSsessionsoronaperportorMACaddressbasis
•ResetallRSconfigurationtoitsdefaultsettings
•ClearallRADIUS‐Snoopingflowtableentriesorperindexentry
•DisplayRSstatistics
RADIUS Session Attributes
TheRADIUSattributesdefiningthe sessionarereturnedintheRADIUSresponseframe.RADIUS
attributesareusedtoconfiguretheuseronthesystem.AttributesexplicitlysupportedbyRSthat
maybeincludedintheRADIUSresponseframeare:
•Idle‐Timeout–IfnoframesareseenfromthisMACaddress,
forthenumberofseconds
configured,thesessionwillbeterminated.
•Session‐Timeout–Thesessionisterminatedafterthenumberofsecondsconfigured.
•Filter‐ID –Definesthepolicyprofile(role)andCLImanagementprivilegelevel,justasit
wouldforanyotherlocalauthenticationagent.
•Tunnel‐Group‐Id–Specifies
theVLANIDforthissession.
Note: Numerous attributes may be supported by the RADIUS client for general RADIUS protocol
support. Such attributes are beyond the scope of this document. This RS implementation does not
interfere with normal RADIUS client attribute support. The list above indicates attributes actually
used by this RADIUS-Snooping application once authentication is successfully completed.