414Configuring AAA for Network Users

Figure 18 on page 414 shows the results of this combination of methods.

Figure 18: Remote Pass-Through or Local Authentication

5 pass fail

WSS switch

local database

RADIUSRADIUS

Server-1Server-2

4

1

2

3

Server-group-1

1

set authentication dot1x ssid mycorp *@example.com pass-through server-group-1 local

Authentication proceeds as follows:

840-9502-0025

1When user Jose@example.com attempts authentication, the WSS switch sends an authentication request to the first AAA method, which is server-group-1.

Because server-group-1contains two servers, the first RADIUS server, server-1, is contacted. If this server responds, the authentication proceeds using server-1.

2If server-1fails to respond, the WSS retries the authentication using server-2. If server-2responds, the authentication proceeds using server-2.

3If server-2does not respond, because the WSS switch has no more servers to try in server-group-1, the WSS attempts to authenticate using the next AAA method, which is the local method.

4The WSS switch consults its local database for an entry that matches Jose@example.com.

5If a suitable local database entry exists, the authentication proceeds. If not, authentication fails and Jose@example.com is not allowed to access the network.

320657-A

Page 414
Image 414
Nortel Networks 2300 manual Remote Pass-Through or Local Authentication