H3C SecPath F1800-A Operation Manual page 440

H3c secpath f1800-a firewall
Hide thumbs Also See for H3C SecPath F1800-A:
Table of Contents

Advertisement

Operation Manual - Security Defence
H3C SecPath F1800-A Firewall
serial interfaces and modems, and then is widely used in the Network Access Server
(NAS) system later.
To obtain the right to access other networks or the right to use some network
resources, you need to set up a connection with the NAS through some network (such
as the telephony network). In this case, the NAS authenticates the user or the
connection. NAS is responsible for sending the AAA information of the user to the
server that runs the RADIUS protocol, which defines how to transmit the user
information and accounting information between the NAS and RADIUS servers.
The RADIUS server receives the user's connection request, completes the
authentication and then sends the configuration information that the user needs back
to the NAS. The authentication information is transmitted with a key between the NAS
and RADIUS so that the user password will not be stolen on insecure networks.
I. RADIUS Message Flow
The RADIUS protocol defines the message flow and message structure for the
message interaction between the client and server. The server adopts the RADIUS
protocol is called RADIUS server.
Figure 5-1
User
Figure 5-1 Message flow between RADIUS client and server
When a user logs in to a network device such as a router or access server, the user
name and password will be sent to it. After the RADIUS client receives the user name
and password, it will send an authentication request to the RADIUS server. On
receiving the valid request, the server completes the authentication and sends the
configuration information that the user needs back to the client. The authentication
information is transmitted with a key between the client and server. In other words, the
authentication information is sent out after being encrypted so that the user
information will not be stolen on insecure networks. The accounting process is similar
to the authentication process.
The login user can be a PPP user for using network resources or an administrator for
configuring or maintaining network devices. In the case that the user information such
as the user name and password is saved on a network device, the authentication is
called the local authentication.
shows a simple message flow defined in the RADIUS protocol.
Username
Router/
Access Server
Request
Response
6-88
Chapter 5 AAA
RADIUS server

Advertisement

Table of Contents
loading
Need help?

Need help?

Do you have a question about the H3C SecPath F1800-A and is the answer not in the manual?

Table of Contents