Implementing Aaa/Radius On Ethernet Switch - Huawei Quidway S3500 Series Operation Manual

Hide thumbs Also See for Quidway S3500 Series:
Table of Contents

Advertisement

Operation Manual - Security
Quidway S3500 Series Ethernet Switches
in PSTN environment or Ethernet switch with access function in Ethernet environment),
NAS, namely RADIUS client end, will transmit user AAA request to the RADIUS server.
RADIUS server has a user database recording all the information of user authentication
and network service access. When receiving user's request from NAS, RADIUS server
performs AAA through user database query and update and returns the configuration
information and accounting data to NAS. Here, NAS controls supplicant and
corresponding connections, while RADIUS protocol regulates how to transmit
configuration and accounting information between NAS and RADIUS.
NAS and RADIUS exchange the information with UDP packets. During the interaction,
both sides encrypt the packets with keys before uploading user configuration
information (like password etc.) to avoid being intercepted or stolen.
II. RADIUS operation
RADIUS server generally uses proxy function of the devices like access server to
perform user authentication. The operation process is as follows: First, the user send
request message (the client username and encrypted password is included in the
message ) to RADIUS server. Second, the user will receive from RADIUS server
various kinds of response messages in which the ACCEPT message indicates that the
user has passed the authentication, and the REJECT message indicates that the user
has not passed the authentication and needs to input username and password again,
otherwise he will be rejected to access.

3.1.3 Implementing AAA/RADIUS on Ethernet Switch

By now, we understand that in the above-mentioned AAA/RADIUS framework,
Quidway Series Ethernet Switches, serving as the user access device or NAS, is the
client end of RADIUS. In other words, the AAA/RADIUS concerning client-end is
implemented on Quidway Series Ethernet Switches. The figure below illustrates the
RADIUS authentication network including Quidway Series Ethernet Switches.
Chapter 3 AAA and RADIUS Protocol Configuration
Huawei Technologies Proprietary
3-2

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents