H3C SR8800-F Configuration Manual page 268

Comware 7 user access
Hide thumbs Also See for SR8800-F:
Table of Contents

Advertisement

The remote system only needs to support PPP, and it does not need to support L2TP.
Authentication and accounting of the remote system can be implemented on the LAC or LNS.
Figure 77 NAS-initiated tunnel establishment process
Remote system
Host A
Device A
(1) Call setup
(2) LCP negotiation
(3) PAP or CHAP
authenticaion
(13) Access the enterprise network
As shown in
Figure
77, the following workflow is used to establish a NAS-initiated tunnel:
1.
A remote system (Host A) initiates a PPP connection to the LAC (Device A).
2.
The remote system and LAC perform PPP LCP negotiation.
3.
The LAC authenticates PPP user information of Host A by using PAP or CHAP.
4.
The LAC sends the authentication information (username and password) to its RADIUS server
(RADIUS server A) for authentication.
5.
RADIUS server A authenticates the user and returns the result.
6.
The LAC initiates an L2TP tunneling request to the LNS (Device B) when the following
conditions exist:
The user passes the authentication.
The user is determined to be an L2TP user according to the username or the ISP domain to
which the user belongs.
7.
If tunnel authentication is needed, the LAC and LNS send CHAP challenge messages to
authenticate each other before successfully establishing an L2TP tunnel.
8.
The LAC and LNS negotiate to establish L2TP sessions.
9.
The LAC sends PPP user information and PPP negotiation parameters to the LNS.
10. The LNS sends the authentication information to its RADIUS server (RADIUS server B) for
authentication.
11. RADIUS server B authenticates the user and returns the result.
12. If the user passes the authentication, the LNS assigns a private IP address to the remote
system (Host A).
13. The PPP user can access internal resources of the enterprise.
LAC
RADIUS server A
(4) Access request
(5) Access accept
(6) Tunnel setup request
(7) CHAP authentication (challenge/response)
(8) Setup a session
(9) Send user information and LCP negotiation
parameters
(12) Assign an IP address
252
LNS
RADIUS server B
Device B
(10) Access request
(11) Acesss accept

Advertisement

Table of Contents
loading

Table of Contents