Introduction To Radius - H3C S7500 Series Operation Manual

Hide thumbs Also See for S7500 Series:
Table of Contents

Advertisement

Operation Manual – AAA & RADIUS & HWTACACS & EAD
H3C S7500 Series Ethernet Switches

1.1.3 Introduction to RADIUS

AAA is a management framework. It can be implemented through more than one
protocol. In practice, the most commonly used protocol for AAA is RADIUS.
I. What is RADIUS
RADIUS (remote authentication dial-in user service) is a distributed information
exchange protocol based on a client/server model. It can prevent unauthorized access
to the network and is commonly used in network environments where both high security
and remote user access are required.
The RADIUS service comprises three components:
Protocol: Based on the UDP/IP layer, RFC 2865 and 2866 define the frame format
and message transfer mechanism of RADIUS, and assign port number 1812 for
authentication and 1813 for accounting.
Server: RADIUS server runs on a central computer or workstation. It stores and
maintains the information about user authentication and network service access.
Client: RADIUS clients run on the dial-in access server device. They can be
deployed anywhere in the network.
RADIUS is based on a client/server model. When serving as a RADIUS client, the
switch passes user information to a designated RADIUS server, and acts (such as
connecting/disconnecting users) depending on the responses returned from the server.
The RADIUS server receives user's connection requests, authenticates users, and
returns all the required information to the switch.
Generally, the RADIUS server maintains the following three databases (as shown in
Figure
1-1):
Users: This database stores information about users (such as user name,
password, protocol used, and IP address).
Clients: This database stores the information about RADIUS clients (such as
shared keys).
Dictionary: This database stores the information used to interpret the attributes
and attribute values of the RADIUS protocol.
Users
Users
Figure 1-1 Databases in a RADIUS server
RADIUS server
RADIUS server
Dictionary
Dictionary
Clients
Clients
1-3
Chapter 1 AAA & RADIUS & HWTACACS
Configuration

Advertisement

Table of Contents
loading

Table of Contents