RADIUS Authentication, Authorization, and Accounting

Contents

Example Configuration on Cisco Secure ACS for MS Windows 5-30

Example Configuration Using FreeRADIUS . . . . . . . . . . . . . . . . . 5-32

VLAN Assignment in an Authentication Session . . . . . . . . . . . . . . . . 5-34

Tagged and Untagged VLAN Attributes . . . . . . . . . . . . . . . . . . . . . . . . 5-35

Additional RADIUS Attributes . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-36

Configuring RADIUS Accounting . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-37 Operating Rules for RADIUS Accounting . . . . . . . . . . . . . . . . . . . . . . 5-39 Steps for Configuring RADIUS Accounting . . . . . . . . . . . . . . . . . . . . . 5-39 1. Configure the Switch To Access a RADIUS Server . . . . . . . . . 5-40

2. Configure Accounting Types and the Controls for

Sending Reports to the RADIUS Server . . . . . . . . . . . . . . . . . . . . 5-42

3. (Optional) Configure Session Blocking and

Interim Updating Options . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-44

Viewing RADIUS Statistics . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-46

General RADIUS Statistics . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-46

RADIUS Authentication Statistics . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-48

RADIUS Accounting Statistics . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . . 5-49

Changing RADIUS-Server Access Order . . . . . . . . . . . . . . . . . . . . . . . 5-50

Messages Related to RADIUS Operation . . . . . . . . . . . . . . . . . . . . . . . 5-53

5-2