Specifications
Before You Begin
18-2 Configuring Communication with RADIUS
Figure 18-1 Wireless Client, AP, RoamAbout switch, and RADIUS Servers
IntheexampleshowninFigure 18‐1,thefollowingeventsoccur:
1. Thewirelessuser(client)requestsanIEEE802.11associationfromtheAP.
2. AftertheAPcreatestheassociation,theRoamAboutswitchsendsanExtensible
AuthenticationProtocol(EAP)identityrequesttotheclient.
3. TheclientsendsanEAPidentityresponse.
4. FromtheEAPresponse,theRoamAboutswitchgetstheclient’susername.TheRoamAbout
switchthensearchesitsAAAconfiguration,attemptingtomatchtheclientʹsusernameagainst
theuserglobsintheAAAconfiguration.
Whenamatchisfound,themethodsspecifiedbythe matchingAAAcommandinthe
RoamAboutswitch
configurationfileindicatehowtheclientistobeauthenticated,either
locallyontheRoamAboutswitch,orviaaRADIUSservergroup.
5. Iftheclientdoesnotsupport802.1X,MSSattemptstoperformMACauthenticationfor the
clientinstead.Inthiscase,iftheswitch’sconfigurationcontainsasetauthenticationmac
commandthatmatchestheclient’sMACaddress,MSSusesthemethodspecifiedbythe
command.Otherwise,MSSuseslocalMACauthentication bydefault.
(ForinformationaboutMACclientauthentication,see“ConfiguringMACAuthentication
andAuthorization”onpage 17‐20.)
Before You Begin
Toensurethatyoucan contacttheRADIUSserversyouplantouseforauthentication,sendthe
pingcommandtoeachonetoverifyconnectivity.
ping ip-address
Youcanthensetupcommunica tionbetweentheswitchandeachRADIUSservergroup.
RAS
with local
database
Wireless
connection
Wired
connection(s)
AP 2AP 1
RADIUS Server 1
RADIUS Server 2
1
3
2
4
Client (with laptop)
Client (with laptop)