Alvarion BreezeMAX Extreme System Manual page 141

Hide thumbs Also See for BreezeMAX Extreme:
Table of Contents

Advertisement

Chapter 4 - Operation and Administration
Embedded Distributed ASN GW Local Authentication - internal NAS is used
for service provisioning and no AAA is required.
External ASN GW - a 3rd party NAS must handle the service provisioning and
also decide if AAA is required.
In order for the RADIUS server to accept requests from its ASN client, a shared
secret is required to be configured on both parties.
For each new network entry, the ASN initiates the creation of an encrypted
EAP-TTLS (EAP-Tunneled Transport Layer Security) tunnel between the user and
the RADIUS server, then continues relaying messages between the two parties
until the tunnel is complete. The purpose of this tunnel is for the user to send its
credentials (username & password) to the RADIUS server, transparent for the
ASN, using a second authentication protocol, MSCHAPv2 (Microsoft
Challenge-Handshake Authentication Protocol version 2).
The RADIUS server then checks the user's credentials against its database and
decides whether or not the user should be accepted and provisioned with services
by the ASN.
Keep-alive and retry mechanisms are implemented on the ASN to overcome
connectivity problems and loss of packets.
When working in internal ASN authentication mode, the settings and flow of the
authentication and service provisioning process are:
The user (i.e. MS) needs to have an authentication type (i.e EAP-TTLS) and a
1
username/password configured in the Registration menu.
The ASN requires the setting of the AAA client (server IP, shared secret and
2
keep-alive settings) and the service definition: Multiple Service Flows and
Service Profiles with all their sub-components.
The configuration of the RADIUS server is the most complex and requires the
3
following:
»
»
BreezeMAX Extreme
Clients database, containing the IPs and shared secrets of all the ASNs
that connect to it;
Users database, containing the users' credentials (username & password),
the corresponding services to be provisioned (the names of the Service
120
ASN-GW Menu
System Manual

Advertisement

Table of Contents
loading

Table of Contents