D-Link DI-3660 [340/506] Radius protocol operation

D-Link DI-3660 [340/506] Radius protocol operation
Command Line Interface Reference Manual
340
authenticate from one router to a non-Cisco router if the non-Cisco router requires RADIUS authentication.
6. Networks using a variety of services. RADIUS generally binds a user to one service model.
6.2.2 RADIUS Protocol Operation
When a user attempts to log in and authenticate to an access server using RADIUS, the following steps occur:
l The user is prompted for and enters a username and password.
l The username and encrypted password are sent over the network to the RADIUS server.
l The user receives one of the following responses from the RADIUS server.
ACCEPT:The user is authenticated.
REJECT:The user is not authenticated and is prompted to reenter the username and password, or access is denied.
CHALLENGE:A challenge is issued by the RADIUS server. The challenge collects additional data from the user.
The ACCEPT or REJECT response is bundled with additional data that is used for EXEC or NETWORK authorization.
You must first complete RADIUS authentication before using RADIUS authorization. The additional data included with
the ACCEPT or REJECT packets consists of the following:
Services that the user can access, including Telnet, rlogin, and PPP, Serial Line Internet Protocol (SLIP), or EXEC
services.
Connection parameters, including the host or client IP address, access list, and user timeouts.
6.2.3 RADIUS Configuration Steps
To configure RADIUS on the Router or access server, you must perform the following tasks:
Use aaa authentication global configuration command to define method lists for RADIUS authentication. For more
information about using the aaa authentication command, refer to the "Configuring Authentication" chapter.
Use line and interface commands to enable the defined method lists to be used. For more information, refer to the
"Configuring Authentication" chapter.
1. Configure Router to RADIUS Server Communication
The RADIUS host is normally a multiuser system running RADIUS server software from Livingston, Merit, Microsoft, or
another software provider. A RADIUS server and a router use a shared secret key to encrypt passwords and exchange
responses. Use the radius server command to specify the RADIUS server and use radius key to specify the shared key.
use the following commands in global configuration directory:
Step Command Purpose
1
radius server ip-address [auth-port
port-number][acct-port portnumber] 
Specify the IP address of the remote RADIUS
server host and assign authentication and
accounting destination port numbers.
2
radius key string  Specify the shared secret key used between the
router and the RADIUS server.
Example: 1. To specify RADIUS server:
[DEFAULT@Router /config/]#radius 
  …… 
  (05)server       Specify a RADIUS server 
  (06)timeout       Time to wait for a RADIUS server to reply 
  (07)vsa        Vendor specific attribute configuration 
  (08)test       Radius test 
  Please Input the code of command to be excute(0-8):  

Содержание

Скачать