Chapter
Erro! Estilo não definido.
Erro! Estilo não definido.
6-19
1. The remote user establishes a connection with ZXDSL 9210 via PPP dial-up.
2. The SCBF of ZXDSL 9210 accepts this remote user’s connection and receives
the user name and password input by the user. The SCBF sends the user’s user
name and password via the G.Link channel to an embedded BAS.
3. Based on such information, this embedded BAS generates a packet called
authentication request. This packet contains the name and password which
identify this equipment information (for example, name and IP address of the
ZXDSL 9210) and user. As the client of RADIUS, the embedded BAS encrypts
the password before sending any packet.
4. The embedded BAS sends authentication request packets to RADIUS server 1.
Upon receiving authentication request packets, RADIUS server 1 decrypts data
to obtain the user name and password, and then authenticates the legality of the
user.
5. If authentication succeeds, RADIUS server 1 will send an "access accepted"
packet to the RADIUS Client (embedded BAS), which contains some
information required for user access, such as the user’s IP address and the
protocol used. Then, the embedded BAS permits the user to access Internet.
6. Upon receiving the authentication success response, the embedded BAS sends
an acknowledgment to the remote user (by means of PAP or CHAP).
7. If authentication fails, RADIUS server 1 will send an "access denied" packet to
the RADIUS Client.
8. When receiving any authentication failure response, the embedded BAS sends
an instruction to a remote user to deny users’ Internet access by means of the
SCBF (by means of PAP or CHAP).
9. The authentication request packet is sent to RADIUS server 1 over network. If
the embedded BAS fails to receive any response, it will retry transmission a
certain number of times. If the active server is down or not reachable, the
authentication request can be sent to the standby RADIUS server 2, and so on.
10. If authentication succeeds, RADIUS server 2 will send an "access accepted"
packet to the RADIUS Client, which contains some information required for
user access, such as the user’s IP address and the protocol used. Then, the
embedded BAS permits the user to access Internet.