Portal Authentication Across Vpns - HP 6600 Security Configuration Manual

Table of Contents

Advertisement

Stateful failover involves the following basic concepts:
Device states:
Independence—A stable running status of a device when it does not establish the failover link
with the other device.
Synchronization—A stable running status of a device when it establishes the failover link with
the other device successfully and is ready for data backup.
User modes:
Stand-alone—Indicates that the user data is stored on the local device only. Currently, the local
device is in independence state or it is in synchronization state but has not synchronized the user
data to the peer device yet.
Primary—Indicates that the user logs in from the local device, and the user data is generated on
the local device. The local device is in synchronization state and ready for receiving and
processing packets from the server.
Secondary—Indicates that the user logs in from the peer device, and the user data is
synchronized from the peer device to the local device. The local device is in synchronization
state. It only receives and processes the synchronization messages and does not process
packets from the server.

Portal authentication across VPNs

Use portal authentication across MPLS VPNs in cases where branches belong to different VPNs that are
isolated from each other, and all portal users in the branches need to be authenticated by the server at
the headquarters. As shown in
The NAS is configured with portal authentication and AAA authentication, both of which support
authentication across VPNs. The NAS can transmit a client's portal authentication packets in a VPN
transparently through the MPLS backbone to the servers in another VPN. This feature implements
centralized client authentication across different VPNs while ensuring the separation of packets of the
different VPNs.
Figure 51 Network diagram for portal authentication across VPNs
VPN 1
Host
VPN 2
Host
This feature is not applicable to VPNs with overlapping address spaces.
This feature is not supported when the router is operating in gateway mode.
Portal authentication configured on MCE devices can also support authentication across VPNs. For
information about MCE, see MPLS Configuration Guide.
Figure
CE
NAS
PE
CE
51, the PE connecting the authentication clients serves as the NAS.
MPLS backbone
PE
P
131
VPN 3
AAA
server
CE
Portal server

Advertisement

Table of Contents
loading

This manual is also suitable for:

Hsr6600

Table of Contents