data:image/s3,"s3://crabby-images/d6e84/d6e847e363077cdca901131a9e5addda295f29c5" alt="H3C WA Series Layer 2 Command Reference Download Page 116"
108
If you run the
ppp authentication-mode
command with the
domain
keyword specified, you must
configure an address pool in the corresponding domain. (You can use the
display domain
command to
display the domain configuration.)
If you configure the
ppp authentication-mode
command without specifying the domain name, the system
checks the username for domain information. If the username contains a domain name, the domain is
used for authentication (If the domain does not exist, the user's access request is denied). If not, the
default domain is used (you can use the
domain default
command to configure the default domain; if no
default domain is configured, the default domain
system
is used by default).
PPP authentication falls into PAP, CHAP, MS-CHAP, and MS-CHAP-V2 authentication.
•
PAP authentication is two-way handshake authentication. The password used is in plain text.
•
CHAP authentication is three-way handshake authentication. The password is in cipher text.
•
MS-CHAP is a three-way handshake authentication. The password is in cipher text.
•
MS-CHAP-V2 is a three-way handshake authentication. The password is in cipher text.
You can configure several authentication modes simultaneously. In addition, you can also use the AAA
authentication algorithm list (if defined) to authenticate users.
In any PPP authentication mode, AAA determines whether a user can pass the authentication through a
local authentication database or an AAA server.
NOTE:
For more information about creating a local user account, configuring its attributes, creating a domain,
and configuring domain attributes, see
Security Configuration Guide.
For authentication on a dial-up interface, configure authentication on both the physical interface and the
dialer interface. Because when a physical interface receives a DCC call request, it first initiates PPP
negotiation and authenticates the dial-in user, and then passes the call to the upper layer protocol.
Related commands:
ppp chap user
,
ppp pap local-user
, and
ppp chap password
;
local-user
and
domain default
(
Security Command Reference
).
Examples
# Configure interface Dialer 1 to authenticate the peer device by using PAP.
<Sysname> system-view
[Sysname] interface Dialer 1
[Sysname-Dialer1] ppp authentication-mode pap domain system
# Configure interface Dialer 2 to authenticate the peer device by using PAP, CHAP, and MS-CHAP.
<Sysname> system-view
[Sysname] interface Dialer 2
[Sysname-Dialer2] ppp authentication-mode pap chap ms-chap domain system
ppp chap password
Syntax
ppp chap password
{
cipher
|
simple
}
password
undo
ppp chap password
View
Dialer interface view