Implementing Aaa/Radius On The Ethernet Switch; Configuring Aaa - 3Com Switch 4500 26-Port Configuration Manual

Switch 4500 family 26-port, 50-port, pwr 26-port, pwr 50-port
Hide thumbs Also See for Switch 4500 26-Port:
Table of Contents

Advertisement

Implementing
AAA/RADIUS on the
Ethernet Switch

Configuring AAA

receiving a user's request from NAS, the RADIUS server performs AAA through
user database query and update and returns the configuration information and
accounting data to NAS. Here, NAS controls users and corresponding connections,
while the RADIUS protocol regulates how to transmit configuration and
accounting information between NAS and RADIUS.
NAS and RADIUS exchange the information with UDP packets. During the
interaction, both sides encrypt the packets with keys before uploading user
configuration information (for example, password) to avoid being intercepted or
stolen.
RADIUS Operation
A RADIUS server generally uses proxy function of the devices such as an access
server to perform user authentication. The operation process is as follows: First,
the user sends a request message (the client username and encrypted password is
included in the message ) to the RADIUS server. Second, the user will receive from
the RADIUS server various kinds of response messages in which the ACCEPT
message indicates that the user has passed the authentication, and the REJECT
message indicates that the user has not passed the authentication and needs to
input their username and password again, otherwise they will be rejected access.
In the above-mentioned AAA/RADIUS framework, the Switch 4500 Family, serving
as the user access device or NAS, is the client end of RADIUS. In other words, the
AAA/RADIUS concerning the client-end is implemented on the Switch 4500. The
figure below illustrates the RADIUS authentication network including 4500
Switches.
Figure 57 Networking when Switch 4500 Units are Applying RADIUS Authentication
PC user1
PC user2
PC user3
PC user4
SW 5500
AAA configuration includes:
Creating/deleting an ISP domain
Configuring relevant attributes of the ISP domain
Creating a local user
Setting attributes of the local user
AAA and RADIUS Protocol Configuration
SW 5500
ISP1
Internet
Internet
Internet
ISP2
Authentication
Server
Accounting
Server1
Accounting
Server2
Authentication
Server
Accounting
Server
203

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents