5 • Authentication
Access Server Administrators’ Reference Guide
54
Setting Up Authentication
NAS Identifier (auNASIdentifier)
This variable is used to identify the access server to the remote authentication server. If this option is blank,
then the access server will use the it’s IP address to identify itself to the remote server.
Accounting Address (auAcctAddress)
This is the IP address of the accounting server. RADIUS also allows for the recording of accounting informa-
tion.
Secondary Accounting Address (auSecondaryAcctAddress)
When using a remote accounting server (such as RADIUS Accounting) this variable provides the IP address of
the accounting server.
Accounting Port (auAcctPort)
This is the UDP port on the accounting server specified in Acct Address that the access server should use to
transfer accounting information. RFC 2139 calls out the port of 1813 as the standard RADIUS accounting
port. Some older implementations of RADIUS use port 1646 as the accounting port.
Accounting Enable (auAccountingEnable)
This is a switch that allows the enabling or disabling the reporting of accounting information on the access
server. The following options are available:
•
enableAccounting—Begin accounting of RADIUS authenticated users.
•
disableAccounting—Disable the accounting feature.
•
enableAccounting-no validation—When a response is received from either the authentication or the
accounting server it is validated using the defined secret. If the secret does not match, the reply packet is
dropped just as if it never existed.
Early versions of the Livingston RADIUS server used a method for encoding the accounting reply packet
that was incorrect. Accounting replies from these servers would therefore be dropped because they could
not be authenticated, eventually resulting in timeouts and shutting the call down with the reason authenAc-
countingTimeout. As a workaround for this issue, the state enableAccountingNoValidation—which does not
check for valid encoding on the accounting reply packet—was added as an option.
Radius Packet Format (auRadiusPacketFormat)
The following options are available:
•
fullrfcPacket—The accept request packet includes Calling-Station-Id and Service-Type RADIUS attributes.
•
minimumrfcPacket—This setting does not include Calling-Station-Id and Service-Type RADIUS
attributes.
Summary of Contents for Access Server
Page 24: ...Contents Access Server Administrators Reference Guide 24 ...
Page 28: ...About this guide Model 2960 RAS Getting Started Guide 28 ...
Page 58: ...5 Authentication Access Server Administrators Reference Guide 58 Static User Authentication ...
Page 94: ...7 Dial In Access Server Administrators Reference Guide 94 Dial In User Statistics window ...
Page 110: ...8 Dial Out Access Server Administrators Reference Guide 110 Dial Out User Statistics window ...
Page 134: ...12 Filter IP Access Server Administrators Reference Guide 134 Defining a filter ...
Page 174: ...17 MFR Version 2 Access Server Administrators Reference Guide 174 ...
Page 184: ...17 MFR Version 2 Access Server Administrators Reference Guide 184 MFR Version 2 Modify ...
Page 190: ...18 RIP Version 2 Access Server Administrators Reference Guide 190 RIP Version 2 Statistics ...
Page 196: ...19 SNMP Access Server Administrators Reference Guide 196 Out ...
Page 248: ...23 TCP Access Server Administrators Reference Guide 248 TCP Details ...
Page 252: ...24 UDP Access Server Administrators Reference Guide 252 Introduction ...
Page 258: ...26 License Access Server Administrators Reference Guide 258 End User License Agreement ...