
Configuring and Troubleshooting Bay Dial VPN Services
2-10
BayStream Multiservice Software Version 7.2
115623B Rev. 00
Using RADIUS for Dynamic IP Address Allocation
Each dial-in user retains a unique IP address for the duration of the dial-in session.
Dial VPN relies on the BSAC RADIUS server on the user’s home network to
provide those addresses, allocating them either statically or dynamically. In static
allocation, the RADIUS administrator assigns specific addresses for specific
users. In dynamic allocation, the administrator allocates a pool of IP addresses
from which the RADIUS server selects an address to assign.
The BayStream administrator configures the IP address of a RADIUS server that
uses dynamic address allocation and also enables dynamic address allocation on
the gateway for that server connection.
When a user dials in to a network using dynamic address allocation, RADIUS
authenticates the user and assigns an IP address from the pool. That user has
exclusive use of that address for the duration of the connection. RADIUS also
maintains a database of assigned addresses. This prevents duplicate assignments if
the server fails.
When the connection ends, the released IP address returns to the pool, at the end
of the assignment queue.
To implement dynamic IP address allocation, Dial VPN requires that the program
BaySecure be installed on the RADIUS server on the customer’s home network.
BaySecure is a robust implementation of the draft IETF RADIUS specification,
compliant with RFC 2058 and RFC 2059.
For information about BaySecure, contact your Bay Networks sales
representative.
Starting the Connection
When a user at a remote node dials a Dial VPN service provider, the NAS first
determines whether this is a tunnel candidate. If so, the NAS first accesses the
TMS database and contacts the gateway, which starts the authentication process.
The gateway gets an IP address from the RADIUS server on the user’s home
network, and the Remote Annex builds a tunnel to a gateway and starts sending
the GRE-encapsulated packets. The process involves the following steps.
1.
A user at a remote node dials the phone number of a Dial VPN service
provider. The user also enters user information, as required by the
connection process.
Summary of Contents for Bay Dial VPN
Page 10: ...x BayStream Multiservice Software Version 7 2 115623B Rev 00 ...
Page 12: ......
Page 14: ......
Page 32: ......
Page 52: ......
Page 68: ......
Page 92: ......
Page 106: ......
Page 146: ......
Page 161: ...Syslog Messages 115623B Rev 00 BayStream Multiservice Software Version 7 2 B 9 ...