Specifications

About AAA for Network Users
RoamAbout Mobility System Software Configuration Guide 17-7
RegardlessofwhetheryouconfiguretheuserandattributesonRADIUSserversortheswitchs
localdatabase,theVLANattributeisrequired.Theotherattributesareoptional.
Accounting
MSSalsosupportsaccounting.Accountingcollectsandsend sinformationusedforbilling,
auditing,andreporting—forexample,useridentities,connectionstartandstoptimes,thenumber
ofpacketsreceivedandsent,andthenumberofbytestransferred.Youcantracksessionsthrough
accountinginformationstoredlocallyoronaremoteRADIUSserver.
Asnetworkusersroam
throughoutaMobilityDomain,accountingrecordstrackthemandtheirnetworkusage.
Summary of AAA Features
Dependingonyournetworkconfiguration,youcanconfigureauthentication,authorization,and
accounting(AAA)fornetworkuserstobe performedlocallyontheRoamAboutSwitchor
remotelyonaRADIUSserver.The numberofusersthatthelocalRoamAboutSwitchdatabasecan
supportdependsonyourplatform.
AAAfornetworkuserscontrols
andmonitorstheiruseofthenetwork:
Classificationforcustomizedaccess.Aswithadministrativeandconsoleusers,youcan
classifynetworkusersthroughusernameglobbing.Basedonthestructuredusername,
differentAAAtreatmentscanbegiventodifferentclassesofuser.Forexample,usersinthe
humanresourcesdepartmentcanbe
authenticateddifferentlyfromusersinthesales
department.
Authenticationforfullorlimitedaccess.IEEE802.1Xnetworkusersareauthenticatedwhen
theyidentifythemselveswithacredential.AuthenticationcanbepassedthroughtoRADIUS,
performedlocallyontheRoamAboutSwitch,oronlypartially“offloaded”totheswitch.
Networkuserswithout
802.1XsupportcanbeauthenticatedbytheMACaddressesoftheir
devices.Ifneither802.1XnorMACauthenticationapplytotheuser,theycanstillbe
authenticatedbyafallthrutype,eitherWebAAAorlastresortauthentication.Thedefault
fallthrutypeisNone,whichdeniesaccesstouserswhodo
notmatchan802.1XorMAC
authenticationrule.
Authorizationforaccesscontrol.Authorizationprovidesaccesscontrolbymeansofsuch
mechanismsasperusersecurityaccesscontrollists(ACLs),VLANmembership,Mobility
Domainassignment,andtimeoutenforcement.Becauseauthorization isalwaysperformedon
networkaccessuserssotheycanusea
particularVLAN,theRoamAboutSwitch
automaticallyusesthesameAAAmethod(RAD IUSservergrouporlocaldatabase)for
authorizationthatyoudefineforausersauthentication.
Localauthorizationcontrol.YoucanoverrideanyAAAassignmentofVLANorsecurityACL
forindividualnetworkusersonaparticularRoamAboutSwitchby
configuringthelocation
policyontheRoamAboutSwitch.
Accountingfortrackingusersandresources.Accountingcollectsandsendsinformation
usedforbilling,auditing,andreporting—forexample,useridentities,connectionstartand
stoptimes,thenumberofpacketsreceivedandsent,andthenumberofbytestransferred.You
cantracksessionsthrough
accountinginformationstoredlocallyoronaremoteRADIUS
server.AsnetworkusersroamthroughoutaMobilityDomain,accountingrecordstrackthem
andtheirnetworkusage.