Remote Authentication Dial-In Service (Radius); Selecting Authentication Method When Multiple Methods Are Validated - Enterasys C5G124-24 Configuration Manual

Fixed switch platforms
Hide thumbs Also See for C5G124-24:
Table of Contents

Advertisement

Figure 10-3

Selecting Authentication Method When Multiple Methods are Validated

SMAC=User 2
SMAC=User 1
Port X

Remote Authentication Dial-In Service (RADIUS)

This section provides details for the configuration of RADIUS and RFC 3580 attributes.
For information about...
How RADIUS Data Is Used
The RADIUS Filter-ID
RFC 3580 — VLAN Authorization
Policy Maptable Response
The Remote Authentication Dial-In User Service (RADIUS) is an extensible protocol used to carry
authentication and authorization information between the switch and the Authentication Server
(AS). RADIUS is used by the switch for communicating supplicant supplied credentials to the
authentication server and the authentication response from the authentication server back to the
switch. This information exchange occurs over the link-layer protocol.
The switch acts as a client to RADIUS using UDP port 1812 by default (configurable in the set
radius command). The authentication server contains a database of valid supplicant user accounts
with their corresponding credentials. The authentication server checks that the information
received from the switch is correct, using authentication schemes such as PAP, CHAP, or EAP. The
authentication server returns an Accept or Reject message to the switch based on the credential
validation performed by RADIUS. The implementation provides enhanced network security by
using a shared secret and MD5 password encryption.
Required authentication credentials depend upon the authentication method being used. For
802.1x and PWA authentication, the switch sends username and password credentials to the
authentication server. For MAC authentication, the switch sends the device MAC address and a
SMAC=User 3
Switch
<User 1, 802.1x, Authenticated, PID=Credit, Applied>
Credit
Policy Role
<User 2, PWA, Authenticated, PID=Sales, Applied>
<User 1, PWA, Authenticated, PID=Credit,
Sales
<User 3, MAC, Authenticated, PID=Guest, Applied>
Policy Role
<User 1, MAC, Authenticated, PID=Guest,
<User 2, MAC, Authenticated, PID=Guest,
Guest
Policy Role
MultiAuth Sessions
Not
Applied>
Not
Applied>
Not
Applied>
Fixed Switch Configuration Guide 10-7
User Authentication Overview
Auth. Agent
802.1X
PWA
MAC
CEP
Refer to page...
10-8
10-8
10-8
10-10

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents