Lucent Technologies MAX 6000 Network Configuration Manual page 201

Hide thumbs Also See for MAX 6000:
Table of Contents

Advertisement

To enforce the second RADIUS lookup, the dialout profile name (pipe-pat-out in this
example) must be different from the name of the called device in the user profile. The
Ascend-Recv-Name attribute specifies the name of the called device, in this case pipe-pat.
In the following second-tier user profile, called party's name is pipe-pat and the
receive-password is pass.
pipe-patUser-Password="pass"
You can disable the double RADIUS lookup by naming the dialout profile with the peer's
name and by omitting the Ascend-Recv-Name attribute. Use the User-Name attribute to
rename the profile (in this case to pipe-pat):
pipe-pat-outUser-Password="ascend"
Message sequence during an outgoing call using two RADIUS lookups
A call using two RADIUS lookups passes through the follow messaging sequence:
1
2
3
4
5
6
7
8
MAX 6000/3000 Network Configuration Guide
Framed-IP-Netmask=255.255.255.0,
Ascend-Dial-Number=90492386067,
Ascend-Data-Svc=Switched-64K,
Ascend-Send-Auth=Send-Auth-CHAP,
Ascend-Send-Secret="passin",
Ascend-Bi-Directional-Auth=Bi-Directional-Auth-Required,
Ascend-Recv-Name="pipe-pat",
Ascend-Route-IP=1
Service-Type=Outbound-User,
Ascend-Route-IP=1"
User-Name="pipe-pat",
Service-Type=Outbound-User,
Framed-Protocol=PPP,
Framed-IP-Address=10.4.8.8,
Framed-IP-Netmask=255.255.255.0,
Ascend-Dial-Number=90492386067,
Ascend-Data-Svc=Switched-64K,
Ascend-Send-Auth=Send-Auth-CHAP,
Ascend-Send-Secret="passin",
Ascend-Bi-Directional-Auth=Bi-Directional-Auth-Required,
Ascend-Receive-Secret="pass",
Ascend-Route-IP=1
The MAX unit requests a dialout profile from RADIUS.
RADIUS sends the dialout profile to the MAX unit.
The MAX unit makes an ISDN call to the remote device.
The ISDN call is connected.
The MAX unit and the called party perform LCP exchanges.
The called party sends a challenge request to the MAX unit.
The MAX unit responds with a challenge response.
The called party informs the MAX unit about whether the first level of authentication has
been successful.
Configuring Individual WAN Connections
Configuring bidirectional CHAP support
4-71

Advertisement

Table of Contents
loading

This manual is also suitable for:

Max 3000

Table of Contents