Specifications

Configuring AAA for Users of Third-Party APs
RoamAbout Mobility System Software Configuration Guide 17-37
Configuring AAA for Users of Third-Party APs
ARoamAboutSwitchcanprovidenetworkaccessforusersassociatedwithathirdpartyAPthat
hasauthenticatedtheuserswithRADIUS.YoucanconnectathirdpartyAPtoaRoamAbout
SwitchandconfiguretheRoamAboutSwitchtoprovideauthorizationforclientswho
authenticateandaccessthenetworkthroughthe
AP.Figure 173showsanexample.
Figure 17-3 RoamAbout Switch Serving as RADIUS Proxy
1. MSSusesMACauthenticationtoauthenticatetheAP.
2. TheusercontactstheAPandnegotiatestheauthenticationprotocoltobeused.
3. TheAP,actingasaRADIUSclient,sendsaRADIUSaccessrequesttothe RoamAboutSwitch.
TheaccessrequestincludestheSSID,theusers
MACaddress,andtheusername.
4. For802.1Xusers,theAPuses802.1Xtoauthenticatetheuser,usingtheRoamAboutSwitchas
itsRADIUSserver.TheRoamAboutSwitchproxiesRADIUSrequestsfromtheAPtoareal
RADIUSserver,dependingontheauthenticationmethodspecifiedintheproxy
authenticationruleforthe
user.
•Fornon802.1Xusers,theAPdoesnotuse802.1X.TheRoamAboutSwitchsendsa
RADIUSqueryforthespecialusernamewebportalssidorlastresortssid,wheressidis
theSSIDname.Thefallthruauthenticationtype(webportalorlastresort)specifiedfor
thewiredauthentication
portconnectedtotheAPdetermineswhichusernameisused.
•ForanyusersofanAPthatsendsSSIDtraffictotheRoamAboutSwitchonanuntagged
VLAN,theRoamAboutSwitchdoesnotuse802.1X.TheRoamAboutSwitchsendsa
RADIUSqueryforthespecialusernamewebportalwiredorlast
resortwired,
dependingonthefallthruauthenticationtype specifiedforthewiredauthenticationport.
5. AftersuccessfulRADIUSauthentication oftheuser(orspecialusername,fornon802.1X
users),MSSassignsauthorizationattributestotheuserfromtheRADIUSserversaccess
acceptresponse.
6. Whentheuserssessionends,thethirdpartyAP
sendsaRADIUSstopaccountingrecordto
theRoamAboutSwitch.TheRoamAboutSwitchthenremovesthesession.
RoamAbout switch
Wired Layer 2
connection
RADIUS server
Layer 2
or Layer 3