Specifications

RADIUS-Snooping Configuration Example
June 03, 2011 Page 9 of 12
WefirstsettheglobalMultiAuthmodetomultionthedistributiontierswitch.Wethensetthe
MultiAuthauthenticationmodetoauthoptfortheupstream(ge.1.510)anddow n stream
(ge.1.1524)ports.
WiththeMultiAuthsettingsconfigured,weenableRADIUSSnoopingatthesystemlevelforthe
distribution
tierswitch.WethenenableRADIUSSnoopingonthetwosetsofportsoverwhichall
RADIUSSnoopingrequestandresponseframeswilltransit.Inthesamecommandlinewe:
•Settheporttimeouttothesystemtimeoutvalue(0)
•Enabledroponallports
•SetthemaximumnumberofRS
sessionsperportto256
WethenconfigurethetwoflowsasspecifiedaboveforUDPport1812andasecretofmysecret.
Wecompletetheconfigurationbychangingthetimeoutvalueatthesystemlevelto15seconds
fromadefaultof20seconds.
Configure the Distribution-tier Switch
SettheMultiAuthmodeforthesystem
System(su)->set multiauth mode multi
SettheMultiAuthauthenticationmodeforeachport
System(su)->set multiauth port mode auth-opt ge.1.5-10,15-24
EnableRSonthissystem:
System(su)->set radius-snooping enable
EnableRSandsetconfigurationforportsonthissystem
System(su)->set radius-snooping port enable drop enabled authallocated 256
ge.1.5-10
System(su)->set radius-snooping port enable drop enabled authallocated 256
ge.1.15-24
ConfigureRSflowtableentries
System(su)->set radius-snooping flow 1 10.10.10.10 50.50.50.50 1812 mysecret
System(su)->set radius-snooping flow 2 10.10.10.20 50.50.50.60 1812 mysecret
ConfigureRStimeoutforthissystem
System(su)->set radius-snooping timeout 15
Managing RADIUS-Snooping on the Distribution-tier Switch
Terminateanactivesessiononportge.1.15:
System(su)->set radius-snooping initialize port ge.1.15
ResetallRSconfigurationtoitsdefaultvalue:
System
(su)->clear radius-snooping all
Clearentryindex2fromtheRSflowtable:
System
(su)->clear radius-snooping flow 2