
NOTE
In RADIUS authentication for an administrator, the AR1200-S checks whether the access type of the
administrator is the same as that specified in the Access-Accept packet sent from the RADIUS server. If
not, administrator fails to be authenticated.
shows packets exchanged between a user, the AR1200-S, and the RADIUS server.
Figure 1-2
RADIUS authentication, authorization, and accounting
Access user
Router
RADIUS
server
User enters user name and
password
Authentication request packet
Access-Accept/Reject packet
Accounting request packet
Accounting response packet
User accesses network resources
User exits
Accounting-stop request packet
Accounting-stop response
packet
1.
A user sends a request packet containing the user name and password to the AR1200-S.
2.
The AR1200-S sends an authentication request packet containing the user name and
password to the RADIUS server.
3.
The RADIUS server authenticates the user name and password. If authentication succeeds,
the RADIUS server sends a RADIUS Access-Accept packet to the AR1200-S. If
authentication fails, the RADIUS server sends a RADIUS Access-Reject packet to the
AR1200-S. The RADIUS Access-Accept packet contains authorization information.
4.
The AR1200-S permits or rejects the user according to the authentication result. If the user
is permitted, the AR1200-S sends an Accounting-Start packet to the RADIUS server.
5.
The RADIUS server sends a response packet to the AR1200-S and starts accounting.
6.
The user starts to access network resources.
7.
The user requests to disconnect from the network. The AR1200-S sends an Accounting-
Stop packet to the RADIUS server.
8.
The RADIUS server sends a response packet to the AR1200-S and stops accounting.
Huawei AR1200-S Series Enterprise Routers
Configuration Guide - Security
1 AAA Configuration
Issue 02 (2012-03-30)
Huawei Proprietary and Confidential
Copyright © Huawei Technologies Co., Ltd.
3