Specifications
About AAA for Network Users
RoamAbout Mobility System Software Configuration Guide 17-7
RegardlessofwhetheryouconfiguretheuserandattributesonRADIUSserversortheswitch’s
localdatabase,theVLANattributeisrequired.Theotherattributesareoptional.
Accounting
MSSalsosupportsaccounting.Accountingcollectsandsend sinformationusedforbilling,
auditing,andreporting—forexample,useridentities,connectionstartandstoptimes,thenumber
ofpacketsreceivedandsent,andthenumberofbytestransferred.Youcantracksessionsthrough
accountinginformationstoredlocallyoronaremoteRADIUSserver.
Asnetworkusersroam
throughoutaMobilityDomain,accountingrecordstrackthemandtheirnetworkusage.
Summary of AAA Features
Dependingonyournetworkconfiguration,youcanconfigureauthentication,authorization,and
accounting(AAA)fornetworkuserstobe performedlocallyontheRoamAboutSwitchor
remotelyonaRADIUSserver.The numberofusersthatthelocalRoamAboutSwitchdatabasecan
supportdependsonyourplatform.
AAAfornetworkuserscontrols
andmonitorstheiruseofthenetwork:
• Classificationforcustomizedaccess.Aswithadministrativeandconsoleusers,youcan
classifynetworkusersthroughusernameglobbing.Basedonthestructuredusername,
differentAAAtreatmentscanbegiventodifferentclassesofuser.Forexample,usersinthe
humanresourcesdepartmentcanbe
authenticateddifferentlyfromusersinthesales
department.
• Authenticationforfullorlimitedaccess.IEEE802.1Xnetworkusersareauthenticatedwhen
theyidentifythemselveswithacredential.AuthenticationcanbepassedthroughtoRADIUS,
performedlocallyontheRoamAboutSwitch,oronlypartially“offloaded”totheswitch.
Networkuserswithout
802.1XsupportcanbeauthenticatedbytheMACaddressesoftheir
devices.Ifneither802.1XnorMACauthenticationapplytotheuser,theycanstillbe
authenticatedbyafallthrutype,eitherWebAAAorlast‐resortauthentication.Thedefault
fallthrutypeisNone,whichdeniesaccesstouserswhodo
notmatchan802.1XorMAC
authenticationrule.
• Authorizationforaccesscontrol.Authorizationprovidesaccesscontrolbymeansofsuch
mechanismsasper‐usersecurityaccesscontrollists(ACLs),VLANmembership,Mobility
Domainassignment,andtimeoutenforcement.Becauseauthorization isalwaysperformedon
networkaccessuserssotheycanusea
particularVLAN,theRoamAboutSwitch
automaticallyusesthesameAAAmethod(RAD IUSservergrouporlocaldatabase)for
authorizationthatyoudefineforauser’sauthentication.
• Localauthorizationcontrol.YoucanoverrideanyAAAassignmentofVLANorsecurityACL
forindividualnetworkusersonaparticularRoamAboutSwitchby
configuringthelocation
policyontheRoamAboutSwitch.
• Accountingfortrackingusersandresources.Accountingcollectsandsendsinformation
usedforbilling,auditing,andreporting—forexample,useridentities,connectionstartand
stoptimes,thenumberofpacketsreceivedandsent,andthenumberofbytestransferred.You
cantracksessionsthrough
accountinginformationstoredlocallyoronaremoteRADIUS
server.AsnetworkusersroamthroughoutaMobilityDomain,accountingrecordstrackthem
andtheirnetworkusage.