Avaya Configuring and Troubleshooting Bay Dial VPN (DVS) Networks Instrukcja Użytkownika Strona 89

  • Pobierz
  • Dodaj do moich podręczników
  • Drukuj
Przeglądanie stron 88
302272-A Rev. 00 6-1
Chapter 6
Configuring the TMS Using Local RADIUS
You can configure the TMS database to use a RADIUS server on the service
provider (ISP) network, instead of using erpcd between the Network Access
Server (NAS) and the local authentication server, as described in Chapter 5.
In the all-RADIUS solution, TMS database functions reside on an enhanced
RADIUS server on the service provider’s network. This allows the elements of the
domain/tunnel decision to reside on the same server as the normal authentication
policies. If no tunnel identifier match exists, the RADIUS server can also be used
to authenticate nontunneled users.
Managing RADIUS-Based TMS
The RADIUS server on the service provider network includes a TMS database,
indexed by the domain name-DNIS pair. The fields in the database are the same as
those described for TMS in Chapter 5.
The RADIUS server parses the domain and DNIS identifier from the Username
field in the access request message and matches these fields against the same
fields in the RADIUS TMS database.
The RADIUS server also maintains an active count of the number of sessions or
links to a particular user from a particular RADIUS client. If this count exceeds
the specified limit, the RADIUS server rejects the authentication request.
Resource tracking starts with the authentication request. The server uses RADIUS
accounting information to confirm and decrement the count.
The NAS recognizes the returned tunnel attributes of the authentication request
and passes the information to its internal TMS client. The TMS client retrieves the
tunnel information it needs from the RADIUS attributes it receives in the access
acceptance message.
Przeglądanie stron 88
1 2 ... 84 85 86 87 88 89 90 91 92 93 94 ... 187 188

Komentarze do niniejszej Instrukcji

Brak uwag