Enterasys Matrix DFE-Gold Series Configuration Guide 26-1
26

RADIUS Snooping Configuration

ThischapterdescribestheRADIUSSnoopingcommandsandhowtousethem.

Understanding RADIUS Snooper

RADIUSSnooper(RS)allowsanetworkmanagertomanagedownstreamconnections,whenthe
fullcomplementofEnterasys’SecureNetworkscapabilitiesisnotdeployedatthenetworkedge.
Thisallowsforthedeploymentoflessfeaturerichedgedevicestoperformbasicaccesscontrolat
thenetworkedge,whilestillprovidingcomplexuserandservicebasedCoSprovisioning,
authorization,andusageauditingtothesession.
ManydownstreamdevicesauthenticatethelocalsessionwithaRADIUSserverthatresides
upstreamofthedistributiontierdevice.RADIUSrequestandresponseframesfromthesedevices
transitthedistributiontierdevice.TheinterceptionofthisRADIUStrafficallowsthedistribution
tierdevicetobuildanauthenticatedsessionfortheendstation,asthoughitwasdirectly
connected.SessionsdetectedbyRSfunctionidenticallytolocalauthenticatedsessionsfromthe
perspectiveoftheEnterasysMultiAuthframework.
TheunencryptedtrafficofthedownstreamdevicespassesthroughthedevicerunningRS,
allowingsuchMultiAuthandSecureNetworkfeaturesassessiontimeout,idletimeout,filterID
attributesandVLANtunnelattributestobeappliedtothetraffic.
TheclientsendsaRADIUSAccessRequestframetotheRADIUSservertoinitiatethe
authenticationprocess.ThisrequestframecontainstheCallingStationIDattribute.TheCalling
StationID,containingtheMACaddress,iscapturedbytheRS.Thesessionisdefinedbythe
attributesreturnedbytheRADIUSserverintheAccessAcceptframe.Theidletimeoutand
sessiontimeoutdictatetheendofthesession,justasifthesessionwasdirectlyconnectedtothe
distributedtierdevicerunningRS.
TheRSflowtablecontainsflowsforeachvalidsessionforthissystem.TheclientIPaddressand
authenticatingRADIUSserverIPaddressaremanuallyenteredintotheRADIUSflowtableonthe
RSenabledswitch.WhenaninvestigatedRADIUSframetransitstheRSenabledportwitha
matchintheflowtable,asessioniscreated.Thesessionbecomesactivewhenitseesaresponsefor
thesessionmatchfromtheRADIUSserver.
Aconfigurabletimerdeterminestheamountoftimethefirmwarewillwaitbeforeterminatinga
sessionbecausenoresponsewasseenfromtheRADIUSserver.
DefaultandnetworkadministratorconfigurableRADIUSpacketdropsettingsexistbasedupon
resourceissuesandvalidationfailure.Packetdropforvalidationfailurescanbeconfiguredona
portbyportbasis.
ToconfigureRSonaswitch:
Note: An Enterasys Feature Guide document that contains a complete discussion on RADIUS
Snooping configuration exists at the following Enterasys web site: http://www.enterasys.com/
support/manuals/