SNR S2989G-48TX-RPS — настройка функций безопасности в сетевых протоколах PPPoE [349/553]

Превью страниц Страница 349 / 553
SNR S2989G-48TX-RPS Руководство по настройке онлайн [349/553] 747284
S2989G-24TX Operation Manual
Chapter 6 Security Function Configuration
6-76
network is also developing from strength to strength, but security problem gradually
becomes the focus, soever the clients or the access device and the network are faced
with security problem (especially from the client) in the current access network. Traditional
Ethernet user can not be identified, traced and located exactly, however in exoteric and
controllable network, identification and location are the basic character and requirement
for user, for example, when supplying the application that use user accounts to login, this
method supplied by PPPoE Intermediate Agent can availably avoid user accounts
embezzled.
There are two stages for PPPoE protocol work: discovery stage and session stage.
Discovery stage is used to obtain MAC address of the remote server to establish a point-
to-point link and a session ID with the server, and session stage uses this session ID to
communicate. PPPoE Intermediate Agent only relates to discovery stage, so we simply
introduce discovery stage.
There are four steps for discovery stage:
1. Client sends PADI packet: The first step, client uses broadcast
address as destination address and broadcast PADI (PPPoE
Active Discovery Initiation) packet to discover access collector in
layer 2 network. Notice: This message may be sent to many
access collector of the network.
2. Broadband Access Server responds PADO packet: The second
step, server responds PADO (PPPoE Active Discovery Offer)
packet to client according to the received source MAC address of
PADI packet, the packet will take sever name and service name.
3. Client sends PADR packet: The third step, client selects a server to
process the session according to the received PADO packet. It may
receives many PADO packets for PADI message of the first step
may be sent to many servers (select the server according to
whether the service information of PADO packet match with the
servce information needed by client). MAC address of the other
end used for session will be known after server is selected, and
send PADR (PPPoE Active Discovery Request) packet to it to
announce server the session requirement.
4. Server responds PADS packet: The fourth step, server establishes
a session ID according to the received PADR packet, this session
ID will be sent to client through PADS (PPPoE Active Discovery
Session-confirmation) packet, hereto PPPoE discovery stage is
completed, enter session stage.
PADT (PPPoE Active Discovery Terminate) packet is an especial packet of PPPoE,

Содержание

666

Изучите этапы настройки безопасности в протоколе PPPoE, включая процесс обнаружения и установления сессии. Узнайте, как защитить учетные записи пользователей.