Configuring Ppp Authentication - Juniper JUNOSE 11.1.X - LINK LAYER CONFIGURATION 4-7-2010 Configuration Manual

For e series broadband services routers - link layer configuration
Table of Contents

Advertisement

Configuring PPP Authentication

Perform the following optional tasks to configure PPP authentication:
NOTE: The JUNOSe software's PPP application accepts null usernames during PAP
and CHAP authentication. When the PPP application receives an authentication
request that includes a null username, PPP passes the request to AAA. To take
advantage of this feature, configure your authentication server to support the use of
null usernames.
ppp authentication
All PPP sessions are enabled by default.
Example
host1(config-if)#ppp shutdown
Use the no version to restart a disabled session.
See ppp shutdown.
Specify one or more PPP authentication types, and select an authentication
virtual router context.
Specify the CHAP challenge length.
Specify the maximum number of retries.
Use to request authentication from a PPP peer and set the authentication method.
To specify the name of a virtual router (VR) to be used as the authentication VR
context, use the virtual-router keyword. Keep the following points in mind when
you use the ppp authentication virtual-router command:
When you specify a VR in the ppp authentication command, AAA does not
query the domain map for the assigned VR context. Instead, AAA uses the
VR specified in the ppp authentication command as the authentication VR
context and issues the authentication request to the authentication server
in the assigned VR context.
If you specify the default VR as the authentication VR context, AAA loosely
binds the user to the default VR. This means that RADIUS can override the
default VR context with a new VR context during the authentication process.
When the ppp authentication virtual-router command specifies the default
VR, AAA returns either the default VR or the VR specified by RADIUS.
If you specify a VR other than the default VR as the authentication VR, AAA
tightly binds the user to the specified VR. This means that RADIUS cannot
override the specified VR context with a new VR context during the
authentication process. When the ppp authentication virtual-router
command specifies a nondefault VR, AAA returns the specified VR.
The router supports the MD5 authentication algorithm for CHAP authentication.
Chapter 8: Configuring Point-to-Point Protocol
Optional Configuration Tasks
283

Advertisement

Table of Contents
loading

This manual is also suitable for:

Junose 11.1.x

Table of Contents