Specifications
Configuring RADIUS Servers
RoamAbout Mobility System Software Configuration Guide 18-3
Configuring RADIUS Servers
Anauthenticationserverauthenticateseachclientwithaccesstoaswitchportbeforemaking
availableanyservicesofferedbytheswitchorthewirelessnetwork.Theauthenticationservercan
resideeitherinthelocaldatabaseontheRoamA boutswitchoronaremoteRADIUSserver.
WhenaRADIUSserverisused
forauthentication,youmustconfigureRADIUSserver
parameters.ForeachRADIUSserver,youmust,ataminimum,settheservername,thepassword
(key),andtheIPaddress.Youcanincludeanyoralloftheotheroptionalparameters.Youcanset
someparametersgloballyfortheRADIUSservers.
ForRADIUS
serversthatdonotexplicitlysettheirowndeadtimeandtimeouttimersand
transmissionattempts,MSSsetsthefollowingvaluesbydefault:
•Deadtime—0(zero)minutes(TheRoamAboutswitchdoesnotdesignateunresponsive
RADIUSserversasunavailable.)
• Transmissionattempts—3
•Timeout(RoamAboutswitchwaitforaserverresponse)—5 seconds
WhenMSSsendsanauthentication
orauthorizationrequesttoaRADIUSserver,MSSwaitsfor
theamountoftheRADIUStimeoutfortheservertorespond.Iftheserverdoesnotre spond,MSS
retransmitstherequest.MSSsend stherequestuptothenumberofretransmitsconfigured.(The
retransmitsettingspecifiesthetotalnumberof
attempts,includingthefirstattempt.)Forexample,
usingthedefaultvalues,MSSsendsarequesttoaserveruptothreetimes,waiting5seconds
betweenrequests.
Ifaserverdoesnotrespondbeforethelastrequestattempttimesout,MSSholdsdownfurther
requeststotheserver,fortheduration
ofthedeadtime.Forexample,ifyousetthedeadtimeto5
minutes,MSSstopssendingrequeststotheunresponsiveserverfor5minutesbeforereattempting
tousetheserver.
Duringtheholddown,itisasifthedeadRADIUSserverdoesnotexist.MSSskipsoveranydead
RADIUSserverstothenextliveserver,orontothenextmethodifnomoreliveserversare
available,dependingonyourconfiguration.Forexample,ifaRADIUSservergroupistheprimary
authenticationmethodandlocalisthesecondarymethod,MSSfailsovertothelocalmethodifall
RADIUSserversintheservergroupareunresponsiveandhaveenteredthedeadtime.
Forfailoverauthenticationorauthorizationtoworkpromptly,EnterasysNetworksrecommends
thatyouchangethedeadtimetoavalueotherthan0.Withthedefaultsetting,thedeadtimeis
neverinvokedandMSSdoesnot
holddownrequeststounresponsiveRADIUSservers.Instead,
MSSattemptstosendeachnewauthenticationorauthorizationrequesttoaserverevenifthe
serveristhoughttobeunresponsive.Thisbehaviorcancauseauthenticationorauthorization
failuresonclientsbecauseMSSdoesnotfailovertothelocalmethod
soonenoughandtheclients
eventuallytimeout.