USER’S GUIDE

The Remote Authentication Dial-In User Service (RADIUS) is a central database supported by the CyberSWITCH. RADIUS operates using two components: an authentication server and client protocols. The RADIUS Server software is typically installed on a UNIX-based or NT-based system that is local to the network. The client protocols allow the CyberSWITCH to communicate with the RADIUS server, ultimately authenticating devices.

When enabled and properly configured, the CyberSWITCH software implements the RADIUS client. The RADIUS client sends packets to the RADIUS Authentication Server. These packets support the following attributes:

User-Name

NAS-IP-Address

CHAP or PAP password

Framed-Protocol

Called-Station-Id

Calling-Station-Id

The following is a typical scenario if the RADIUS Server is activated: when a remote device needs to be authenticated, the system will send an access request to the primary RADIUS Server. After the configured time interval the system will send an access request retry if the primary server does not respond. After the configured number of retries, the system will request authentication information from the secondary server if one is configured. The connection will be released if neither server responds to the access requests.

The section titled On-node Device Table Security Requirements describes the device authentication information required for each type of remote device. The information you need to configure depends upon what you have configured for the CyberSWITCH operating mode (bridging and/or routing), and the security options you select.

To configure the RADIUS Server itself, refer to the RADIUS Authentication Server User’s Guide. If you have Internet access, you may obtain this guide by following the steps outlined below:

Use your Web browser to get to the following address: http:// service.nei.com

From the resulting screen, click on Anonymous.

Click on the Radius directory.

Click on the Docs directory. The guide will be under this directory.

CONFIGURING A RADIUS ACCOUNTING SERVER

Refer to the preliminary steps described in Configuring a RADIUS Authentication Server. These also apply to RADIUS Accounting.

USING CFGEDIT

1.From CFGEDIT Main Menu, select (3) Security.

2.Select (5) Off-node Server Information.

3.Select (5) RADIUS Accounting. A screen similar to the following will display:

212 CyberSWITCH

Page 212
Image 212
Enterasys Networks CSX7000, CSX5500, CSX6000 Configuring a Radius Accounting Server, Select 5 Off-node Server Information