
Configuring RADIUS
1-8
308640-14.00 Rev 00
Using RADIUS with a Dial Service
To use RADIUS authentication with a dial service, you must configure at least one
of the three Nortel Networks dial services: dial-on-demand, dial backup, or
bandwidth-on-demand. The dial service enables the router to activate a dial-up
connection when it receives an incoming call. For information about configuring a
dial service, refer to Configuring Dial Services.
Configuring Vendor-Specific Attributes (VSAs) for Authentication
To authenticate a remote caller, the RADIUS client must identify the router
placing the call. Identifying the remote caller is accomplished by configuring the
caller’s Challenge Handshake Authentication Protocol (CHAP) or Password
Authentication Protocol (PAP) name and secret so that it maps the local circuits to
the name of the remote caller.
• In slots not configured with RADIUS, identify the remote caller by
configuring the router’s caller resolution table. (For information about caller
resolution tables, refer to Configuring Dial Services.)
• In slots configured with RADIUS and dial circuits, configure the
vendor-specific attributes (VSAs) on the RADIUS server. The required VSA
is Bay-Local-IP-Address, which specifies the IP address of the local port. This
VSA must match the IP address of the interface receiving the call.
When a call comes in that needs authentication, the RADIUS client first checks
the router’s caller resolution table for an entry that identifies the caller.
• If the caller is authorized, the local router maps the caller to a local circuit,
and then activates that circuit.
• If that fails, and RADIUS is configured, a request is sent to the RADIUS
server for authentication.
Note:
Do not configure a caller resolution table if you plan to use
vendor-specific attributes.
Comentários a estes Manuais