Top Banner
Connecting the Dots: Integrating RADIUS to Network Measurement and Monitoring TREX Workshop 2013 30th of October 2013 Karri Huhtanen (Arch Red Oy, Open System Consultants)
11

Connecting the Dots: Integrating RADIUS to Network Measurement and Monitoring

Jun 21, 2015

Download

Technology

Karri Huhtanen

Nowadays data of the network usage is too often separated to various network components all around service provider network. Utilising RADIUS more efficiently is one approach to collect more data about network usage, combining it to network measurement, monitoring and management makes it even more efficient tool to use to get a real network situation and history overview.
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Connecting the Dots: Integrating RADIUS to Network Measurement and Monitoring

Connecting the Dots: Integrating RADIUS to Network Measurement and Monitoring

TREX Workshop 2013 30th of October 2013

!Karri Huhtanen

(Arch Red Oy, Open System Consultants)

Page 2: Connecting the Dots: Integrating RADIUS to Network Measurement and Monitoring

Finnish and Australianengineers

Since 2003 Since 1993

developed, supported and consulted by

Page 3: Connecting the Dots: Integrating RADIUS to Network Measurement and Monitoring

RADIUSAuth.

NetworkManagement,

Monitoring

InfraServices

(DHCP, DNS, etc.)

Access devices,e.g. WiFi controllers,

DSLAMs etc.

Devices

Servers

People

Page 4: Connecting the Dots: Integrating RADIUS to Network Measurement and Monitoring

RADIUSAuth.

NetworkManagement,

Monitoring

InfraServices

(DHCP, DNS, etc.)

Access devices,e.g. WiFi controllers,

DSLAMs etc.

Devices

Servers

People

• Network monitoring is done by polling each component

• Network management is done via pushing configurations to components

Page 5: Connecting the Dots: Integrating RADIUS to Network Measurement and Monitoring

RADIUSAuth.

NetworkManagement,

Monitoring

InfraServices

(DHCP, DNS, etc.)

Access devices,e.g. WiFi controllers,

DSLAMs etc.

Devices

Servers

People

Most of the network components and devices use infra services, which may have no connection to other systems

Page 6: Connecting the Dots: Integrating RADIUS to Network Measurement and Monitoring

RADIUSAuth.

NetworkManagement,

Monitoring

InfraServices

(DHCP, DNS, etc.)

Access devices,e.g. WiFi controllers,

DSLAMs etc.

Devices

Servers

People

RADIUS is used only for access control (authentication)

Page 7: Connecting the Dots: Integrating RADIUS to Network Measurement and Monitoring

RADIUSAuth.

NetworkManagement,

Monitoring

InfraServices

(DHCP, DNS, etc.)

Access devices,e.g. WiFi controllers,

DSLAMs etc.

Devices

Servers

People

• Actual data about network (usage) is spread all around.

• Some data may be lost as it is not collected from sources regularly.

• Combining data is limited to possibly some network availability data and mining logs.

• Administrative access to network equipment, servers etc. is not controlled by using access level and roles.

Page 8: Connecting the Dots: Integrating RADIUS to Network Measurement and Monitoring

So what can RADIUS do?

Page 9: Connecting the Dots: Integrating RADIUS to Network Measurement and Monitoring

RADIUS AAA

NetworkManagement,

Monitoring AND Measurement

InfraServices

(DHCP, DNS, etc.)

Access devices,e.g. WiFi controllers,

DSLAMs etc.

Devices

Servers

People

• RADIUS for Authentication AND Accounting AND Authorization

• Dialog between network components, infrastructure and services

• Collecting all data • Dynamic configuration

Page 10: Connecting the Dots: Integrating RADIUS to Network Measurement and Monitoring

How? Well… among others …

• RADIUS authentication and accounting

• TACACS authentication, accounting and authorisation

• Radiator RADIUS server integration capabilities, additional dynamic modules

• AAA/IdM protocol translation (LDAP, SAML, etc.)

• RADIUS/TACACS proxying/roaming for federated authentication

• 802.1X access control and authorisation

• Various two-factor authentication solutions

• Did I mention Radiator RADIUS server is based on Perl?

Page 11: Connecting the Dots: Integrating RADIUS to Network Measurement and Monitoring

More?

my contact information !

Karri Huhtanen [email protected]

http://www.archred.com/ !

these and more slides: http://www.slideshare.net/

khuhtanen/