Specifications

RADIUS-Snooping Overview
June 03, 2011 Page 5 of 12
Figure 1 RADIUS-Snooping Overview
Figure 1onpage 5illustratestheRADIUSrequestframeandRADIUSresponseframepaths.As
theRADIUSrequestframefromtheRADIUSclientedgedevicetransitsthedistributiontier
switch,itissnooped.AnRSsessioniscreatedonthedistribution tierswitch,if:
•RADIUSsnoopingisenabledontheswitch
•RADIUS
Snoopingisenabledontheport
•TheRADIUSclientedgedeviceandRADIUSservercombinationaredefinedintheRADIUS
snoopingflowtable
WhentheRADIUSserverreceivestherequest,theauthenticatingdeviceisfirstvalidated.After
validatingthe authenticatingdevice,theserverauthenticatestheusersessionitselfbasedon
passedusername
andpasswordattributes.Ifthatsucceedsanaccessacceptmessagecontaining
RADIUSattributesissentbacktotheclient,otherwiseanaccessrejectmessageissentback.Asthe
RADIUSresponseframetransitsthedistributiontierswitch,theRADIUSattributescontainedin
theresponseframeareappliedtothissession,
ifanRSsessionwascreatedforthisclientserver
combinationandthesessionhasnottimedout.
RADIUS Server
Distribution-Tier
Switch
Edge Switch
The RADIUS Response Frame
1
3
2
RADIUS Request Frame is snooped
by the distribution-tier switch
RADIUS Request Frame
RADIUS Response Frame
RADIUS Response Frame is
snooped by the distribution-tier
switch