Security/Ppp; Security/Filter Defines - ADTRAN Express L128FP User Manual

Adtran idsl router/bridge user manual
Table of Contents

Advertisement

the retry count, the secondary server (if defined) is tried. If the secondary
server does not respond within the retry count, the PPP peer (or Telnet
session) is not authenticated and is dropped. The default is 5.
»» Security/PPP
Write security: 1; Read security: 2
The PPP peer can be authenticated using three standard methods:
PAP (Password Authentication Protocol), CHAP (Challenge Hand-
shake Protocol) and EAP (Extensible Authentication Protocol). The
strength of the authentication is determined in the order EAP, CHAP,
followed by PAP, where EAP is the strongest and PAP is the weakest.
PAP is a clear-text protocol, which means it is sent over the PPP link
in a readable format. Care must be taken not to allow highly sensitive
passwords to become compromised using this method. CHAP and
EAP use a one-way hashing algorithm which makes it virtually im-
possible to determine the password. EAP has other capabilities which
allow more flexibility than CHAP.
The following selections are possible:
PAP, CHAP or
EAP (def)
CHAP or EAP The Express L128FP will ask for EAP during the
EAP
»» Security/Filter Defines
The Express L128FP can filter packets based on certain parameters
within the packet. The method used by the Express L128FP allows the
highest flexibility for defining filters and assigning them to a profile.
The filters are set up in two steps: (1) defining the packet types, and (2)
adding them to a list under the PPP profile or DLCI map. See the sec-
tion DLCI Mapping/Filters on page 3-39 for examples of how to set up
61202070L4-20
Chapter 3. Terminal Menu Operation and Structure
The Express L128FP will ask for EAP during the
first PPP LCP negotiation and allow the PPP
peer to negotiate down to CHAP or PAP.
first PPP LCP negotiation and allow the PPP
peer to negotiate down to CHAP but not PAP.
The Express L128FP will only allow EAP to be ne-
gotiated. If the PPP peer is not capable of doing
EAP, then the connection will not succeed.
Express L128FP User Manual
3-27

Advertisement

Table of Contents
loading

Table of Contents