100
CN4093 Application Guide for N/OS 8.4
RADIUS Authentication and Authorization
Enterprise
NOS
supports
the
RADIUS
(Remote
Authentication
Dial
‐
in
User
Service)
method
to
authenticate
and
authorize
remote
administrators
for
managing
the
switch.
This
method
is
based
on
a
client/server
model.
The
Remote
Access
Server
(RAS)—the
switch—is
a
client
to
the
back
‐
end
database
server.
A
remote
user
(the
remote
administrator)
interacts
only
with
the
RAS,
not
the
back
‐
end
server
and
database.
RADIUS
authentication
consists
of
the
following
components:
A
protocol
with
a
frame
format
that
utilizes
UDP
over
IP
(based
on
RFC
2138
and
2866)
A
centralized
server
that
stores
all
the
user
authorization
information
A
client,
in
this
case,
the
switch
The
CN4093—acting
as
the
RADIUS
client—communicates
to
the
RADIUS
server
to
authenticate
and
authorize
a
remote
administrator
using
the
protocol
definitions
specified
in
RFC
2138
and
2866.
Transactions
between
the
client
and
the
RADIUS
server
are
authenticated
using
a
shared
key
that
is
not
sent
over
the
network.
In
addition,
the
remote
administrator
passwords
are
sent
encrypted
between
the
RADIUS
client
(the
switch)
and
the
back
‐
end
RADIUS
server.
How RADIUS Authentication Works
1.
Remote
administrator
connects
to
the
switch
and
provides
user
name
and
password.
2.
Using
Authentication/Authorization
protocol,
the
switch
sends
request
to
authentication
server.
3.
Authentication
server
checks
the
request
against
the
user
ID
database.
4.
Using
RADIUS
protocol,
the
authentication
server
instructs
the
switch
to
grant
or
deny
administrative
access.
Summary of Contents for Flex System Fabric CN4093
Page 27: ... Copyright Lenovo 2017 27 Part 1 Getting Started ...
Page 28: ...28 CN4093 Application Guide for N OS 8 4 ...
Page 58: ...58 CN4093 Application Guide for N OS 8 4 ...
Page 72: ...72 CN4093 Application Guide for N OS 8 4 ...
Page 85: ... Copyright Lenovo 2017 85 Part 2 Securing the Switch ...
Page 86: ...86 CN4093 Application Guide for N OS 8 4 ...
Page 98: ...98 CN4093 Application Guide for N OS 8 4 ...
Page 112: ...112 CN4093 Application Guide for N OS 8 4 ...
Page 136: ...136 CN4093 Application Guide for N OS 8 4 ...
Page 156: ...156 CN4093 Application Guide for N OS 8 4 ...
Page 192: ...192 CN4093 Application Guide for N OS 8 4 ...
Page 228: ...228 CN4093 Application Guide for N OS 8 4 ...
Page 229: ... Copyright Lenovo 2017 229 Part 4 Advanced Switching Features ...
Page 230: ...230 CN4093 Application Guide for N OS 8 4 ...
Page 298: ...298 CN4093 Application Guide for N OS 8 4 ...
Page 382: ...382 CN4093 Application Guide for N OS 8 4 ...
Page 392: ...392 CN4093 Application Guide for N OS 8 4 ...
Page 416: ...416 CN4093 Application Guide for N OS 8 4 ...
Page 452: ...452 CN4093 Application Guide for N OS 8 4 ...
Page 466: ...466 CN4093 Application Guide for N OS 8 4 ...
Page 496: ...496 CN4093 Application Guide for N OS 8 4 ...
Page 508: ...508 CN4093 Application Guide for N OS 8 4 ...
Page 510: ...510 CN4093 Application Guide for N OS 8 4 ...
Page 514: ...514 CN4093 Application Guide for N OS 8 4 ...
Page 538: ...538 CN4093 Application Guide for N OS 8 4 ...
Page 539: ... Copyright Lenovo 2017 539 Part 7 Network Management ...
Page 540: ...540 CN4093 Application Guide for N OS 8 4 ...
Page 554: ...554 CN4093 Application Guide for N OS 8 4 ...
Page 576: ...576 CN4093 Application Guide for N OS 8 4 ...
Page 596: ...596 CN4093 Application Guide for N OS 8 4 ...
Page 604: ...604 CN4093 Application Guide for N OS 8 4 ...
Page 609: ... Copyright Lenovo 2017 609 Part 9 Appendices ...
Page 610: ...610 CN4093 Application Guide for N OS 8 4 ...
Page 626: ...626 CN4093 Application Guide for N OS 8 4 ...
Page 633: ......
Page 634: ...Part Number 00MY375 Printed in USA IP P N 00MY375 ...