
Dial VPN Layer 2 Tunneling
303509-A Rev 00 2-9
Figure 2-3. Tunnel Authentication Control Messages
After tunnel authentication is complete, it need not be repeated for other calls to
the same LAC.
RADIUS User Authentication
RADIUS user authentication is enabled by default on the Bay Networks LNS; you
must configure this feature so that the LNS can validate the remote user’s identity
before allowing access to the network.
The network administrator at the corporate site must configure a RADIUS server
with the names and passwords of authorized users. When the LNS receives a call,
it forwards an authentication request with the user information to the RADIUS
server, which verifies whether the user is authorized. If the user is permitted
access to the network, the RADIUS server replies with an acknowledgment
message and the appropriate IP address information for that user to make a
connection.
For more information about configuring Bay Networks routers as RADIUS
servers, see Configuring RADIUS.
L2T0006A
LAC
ISP network
LNS
Corporate network
PPP connection
SCCRQ
SCCCN
SCCRP
tunnel request and challenge
tunnel response, challenge response,
and LNS challenge
challenge response
Komentarze do niniejszej Instrukcji