[RADIATOR] Radiator Access Control on a Cisco Switch

Hugh Irvine hugh at open.com.au
Wed Apr 29 02:47:01 CDT 2009


Hello Gilbert -

Can you send me the contents of a sample RADIUS request from the switch?

Normally the MAC addresses are contained in the Calling-Station-Id and  
Called-Station-Id, so it is usually quite simple to configure a  
suitable AuthBy.

Assuming the MAC address of the client device is contained in the  
Calling-Station-Id attribute, you can simply use something like the  
following:


.....

	<AuthBy .....>

		AuthenticateAttribute Calling-Station-Id

		.....

	</AuthBy>

.....



Can you tell me what user database you are going to be using?

regards

Hugh


On 29 Apr 2009, at 09:15, Gilbert T. Gutierrez, Jr. wrote:

> I have downloaded the latest version of Radiator (4-4.1) and  
> compiled and
> installed it on my radius servers (Centos/RHEL 5).
>
> I have a handful of Cisco 3550 switches that I have over one thousand
> customers terminating on.  I want to control these customers using  
> only
> their MAC address and Radiator if possible.  I only want a customer  
> to take
> up one IP address and not be able to step on another customer.   
> Currently I
> do this by putting each customer on their own VLAN which is a hassle.
>
> I looked into Cisco Network Admission Control (NAC) (Bought the  
> books) and
> cannot find the right way to approach this.  What seemed to come  
> closest to
> what I am trying to do is EAP-FAST, but I am not sure.  I am having  
> a heck
> of a time parsing through all the data on the web regarding eap.  It  
> seems
> that all of the data I pull up is regarding wireless access points.
>
> Does anyone have any pointers for me on this subject?
>
> Thank you in advance for the help.
>
> Gilbert Gutierrez
>
>
>
>
>
> _______________________________________________
> radiator mailing list
> radiator at open.com.au
> http://www.open.com.au/mailman/listinfo/radiator



NB:

Have you read the reference manual ("doc/ref.html")?
Have you searched the mailing list archive (www.open.com.au/archives/radiator)?
Have you had a quick look on Google (www.google.com)?
Have you included a copy of your configuration file (no secrets),
together with a trace 4 debug showing what is happening?
Have you checked the RadiusExpert wiki:
http://www.open.com.au/wiki/index.php/Main_Page

-- 
Radiator: the most portable, flexible and configurable RADIUS server
anywhere. Available on *NIX, *BSD, Windows, MacOS X.
Includes support for reliable RADIUS transport (RadSec),
and DIAMETER translation agent.
-
Nets: internetwork inventory and management - graphical, extensible,
flexible with hardware, software, platform and database independence.
-
CATool: Private Certificate Authority for Unix and Unix-like systems.




More information about the radiator mailing list