1-6
Re-DHCP authentication process
Figure 1-3
Re-DHCP authentication process
The re-DHCP authentication process is as follows:
Step 1 through step 6 are the same as those in the direct authentication/Layer 3 portal authentication
process.
7) After receiving an authentication acknowledgment message, the authentication client obtains a
new public IP address through DHCP and notifies the portal server that it has obtained a public IP
address.
8) The portal server notifies the access device that the authentication client has obtained a new public
IP address.
9) Detecting the change of the IP address by examining ARP packets received, the access device
notifies the portal server of the change.
10) The portal server notifies the authentication client of logon success.
11) The portal server sends a user IP address change acknowledgment message to the access
device.
With extended portal functions, the process includes two additional steps:
12) The security policy server exchanges security authentication information with the client to check
whether the authentication client meets the security requirements.
13) The security policy server authorizes the user to access unrestricted resources based on the
security configuration for the user. The authorization information is stored on the access device
and used by the access device to take control of user access.
Portal Configuration Task List
Complete these tasks to configure portal authentication:
Содержание S7906E - Switch
Страница 82: ...1 4 DeviceA interface tunnel 1 DeviceA Tunnel1 service loopback group 1...
Страница 200: ...1 11 DeviceB display vlan dynamic No dynamic vlans exist...
Страница 494: ...ii Displaying and Maintaining Tunneling Configuration 1 45 Troubleshooting Tunneling Configuration 1 45...
Страница 598: ...ii...
Страница 1757: ...4 9...
Страница 1770: ...6 4...
Страница 2017: ...2 11 Figure 2 3 SFTP client interface...
Страница 2062: ...i Table of Contents 1 URPF Configuration 1 1 URPF Overview 1 1 What is URPF 1 1 How URPF Works 1 1 Configuring URPF 1 2...
Страница 2238: ...1 16 DeviceA cfd linktrace service instance 1 mep 1001 target mep 4002...
Страница 2442: ...2 4 Set the interval for sending Syslog or trap messages to 20 seconds Device mac address information interval 20...