246
Enabling PPP user blocking
About PPP user blocking
This feature blocks a PPP user for a period if the user fails authentication consecutively for the
specified number of times within the detection period. This feature helps prevent illegal users from
using the method of exhaustion to obtain the password, and reduces authentication packets sent to
the authentication server. Packets from the blocked users will be discarded during the blocking
period, and will be processed when the blocking period expires.
This feature identify users by username and domain name. Users that have the same username but
belong to different domains are processes as different users.
Procedure
To enable PPP user blocking:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enable PPP user blocking.
ppp authentication chasten
auth-failure auth-period
blocking-period
By default, PPP user blocking is
disabled.
Configuring the NAS-Port-Type attribute
The NAS-Port-Type attribute is used for RADIUS authentication and accounting. For information
about the NAS-Port-Type attribute, see RFC 2865.
To configure the NAS-Port-Type attribute:
Step Command
Remarks
1.
Enter system view.
system-view
N/A
2.
Enter VT interface view.
interface virtual-template
number
N/A
3.
Configure the
NAS-Port-Type attribute.
nas-port-type
{
802.11
|
adsl-cap
|
adsl-dmt
|
async
|
cable
|
ethernet
|
g.3-fax
|
hdlc
|
idsl
|
isdn-async-v110
|
isdn-async-v120
|
isdn-sync
|
piafs
|
sdsl
|
sync
|
virtual
|
wireless-other
|
x.25
|
x.75
|
xdsl
}
By default, the NAS-Port-Type
attribute is determined by the
service type and link type of the
PPP user (see
Table 14 Default NAS-Port-Type attribute
Service type
Link type
Nas-port-type
attribute
PPPoE Any
ethernet
L2TP Any
virtual