Specifications

About AAA for Network Users
17-2 Configuring AAA for Network Users
Authentication
Whenauserattemptstoaccessthenetwork,MSSchecksforanauthenticationrulethatmatches
thefollowingparameters:
•Forwirelessaccess,theauthenticationrulemustmatchtheSSIDtheuserisrequesting,and
theusersusernameorMACaddress.
•Foraccessonawiredauthenticationport,theauthenticationrulemust
matchtheusers
usernameorMACaddress.
Ifamatchingruleisfound,MSSthenchecksRADIUSserversortheswitch’slocaluserdatabase
forcredentialsthatmatchthosepresentedbytheuser.Dependingonthetypeofauthentication
rulethatmatchestheSSIDorwiredauthenti cationport,therequiredcredentials
arethe username
orMACaddress,andinsomecases,apassword.
Eachauthenticationrulespecifieswheretheusercredentialsarestored.Thelocationcanbea
groupofRADIUSserversortheswitch’slocaldatabase.Ineithercase,ifMSShasan
authenticationrulethatmatchesontherequiredparameters,
MSScheckstheusernameorMAC
addressoftheuserand,ifrequired,thepasswordtomakesuretheymatchtheinformation
configuredontheRADIUSserversorinthelocaldatabase.
TheusernameorMACaddresscanbeanexactmatchorcanmatchausergloborMACaddress
glob,whichallowwildcardstobeusedforallorpartoftheusernameorMACaddress.(Formore
informationaboutglobs,seeAAAToolsforNetworkUsersonpage 178.)
Authentication Types
MSSprovidesthefollowingtypesofauthentication:
IEEE802.1X—Ifthenetworkusersnetworkinterfacecard(NIC)supports802.1X,MSSchecks
foran802.1Xauthenticationrulethatmatchestheusername(andSSID,ifwirelessaccessis
requested),andthatusestheExtensibleAuthenticationProtocol(EAP)requestedbytheNIC.
Ifamatching
ruleisfound,MSSusestherequestedEAPtochecktheRADIUSservergroupor
localdatabasefortheusernameandpasswordenteredbytheuser.Ifmatchinginformationis
found,MSSgrantsaccesstotheuser.
•MACIfthe usernamedoesnotmatchan802.1Xauthentication rule,buttheMACaddress
of
theusersNICorVoiceoverIP(VoIP)phoneandtheSSID(ifwireless)domatchaMAC
authenticationrule,MSScheckstheRADIUSservergrouporlocaldatabaseformatchinguser
information.IftheMACaddress(andpassword,ifonaRADIUSserver)matches,MSSgrants
access.Otherwise,
MSSattemptsthefallthruauthenticationtype,whichcanbeWeb,last
resort,ornone.(FallthruauthenticationisdescribedinmoredetailinAuthentication
Algorithmonpage 173.)
•WebAnetworkuserattemptstoaccessawebpageoverthenetwork.TheRoamAbout
switchinterceptstheHTTPorHTTPSrequestandserves
aloginWebpagetotheuser.The
userenterstheusernameandpassword,andMSScheckstheRADIUSservergrouporlocal
databaseformatchinguserinformation.Iftheusernameandpasswordmatch,MSSredirects
theusertothewebpagesherequested.Otherwise,MSSdeniesaccesstotheuser.
Lastresort—Anetworkuserrequestsaccesstothenetwork,withoutenteringausernameor
password.MSSchecksforalastresortauthenticationrulefortherequestedSSID(orfor
wired,iftheuserisonawiredauthenticationport).Ifamatchingruleisfound,MSSchecks
theRADIUSserver
grouporlocaldatabaseforusernamelastresortwired(forwired
authenticationaccess)orlastresortssid,wheressidistheSSIDrequestedbytheuser.Ifthe
userinformationisonaRADIUSserver,MSSalsochecksforapassword.