Configuring Aaa Authentication For Dhcp Local Server Standalone Mode - Juniper JUNOSE 11.1.X - BROADBAND ACCESS CONFIGURATION GUIDE 6-4-2010 Configuration Manual

For e series broadband services routers - broadband access
Table of Contents

Advertisement

NOTE: Configuring a new grace period that is shorter than the address pool current
grace period immediately terminates any existing address leases that are in the grace
period state and that have already exceeded the length of the new grace period.
An address continues to be counted against the address pool resources while in a
grace period. For example, if the address pool is exhausted, a new address cannot
be assigned to other clients.
Client address leases enter the grace period in two ways the lease might expire or
the address can be explicitly released by the client. In both cases the address remains
unavailable to other clients and can only be reapplied to the original client during
the grace period. The address is released back to the address pool if the grace period
expires before the address is reapplied to the original client.
When you configure a grace period, by default it is applied to address leases that
expire, but not to addresses that are released by clients. However, you can optionally
apply the grace period to released addresses.

Configuring AAA Authentication for DHCP Local Server Standalone Mode

The DHCP local server enables you to optionally configure AAA-based authentication
of standalone mode DHCP clients. In addition to providing increased security, AAA
authentication also provides RADIUS-based input to IP address pool selection for
standalone mode clients. By default, clients are not authenticated in standalone
mode.
Typically, an incoming DHCP client does not provide a username therefore, the
DHCP local server constructs a username based on the user's attachment parameters
and optional DHCP parameters. AAA uses the constructed username to authenticate
the incoming client and create the AAA subscriber record for the client. The
information in the AAA subscriber record is then used to determine the IP address
pool from which to assign the address for the DHCP client. You can include the
following elements in the username:
Attachment Parameters
domain
user prefix
Configuring AAA Authentication for DHCP Local Server Standalone Mode
Chapter 19: Configuring DHCP Local Server
DHCP Parameters
circuit ID
circuit type
MAC address
option 82
virtual router name
487

Advertisement

Table of Contents
loading

Table of Contents